Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.38%—Devolutions Powershell Universal24/7/202629/7/2026
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
AplazadaBaja (2.1)0.30%—ShellyAIHome-assistant CoreAI21/7/202622/7/2026
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against…
AnalizadaMedia (6.5)0.44%—Devolutions Powershell Universal29/6/20262/7/2026
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
AnalizadaAlta (8.7)0.60%—Shell-quote Project Shell-quote25/6/202626/6/2026
shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled…
AnalizadaMedia (6.5)0.35%—Oracle Mysql Shell17/6/202622/6/2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks of this…
AnalizadaAlta (8.5)0.33%—Oracle Mysql Shell17/6/202622/6/2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL…
AnalizadaMedia (6.5)0.19%—Oracle Mysql Shell17/6/202622/6/2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks…
AnalizadaCrítica (9.9)0.55%—Oracle Mysql Shell17/6/202622/6/2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks…
AnalizadaMedia (5.3)0.37%—Ironmansoftware Powershell Universal12/6/202617/6/2026
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
AplazadaCrítica (9.2)0.82%—Shell-quoteAI22/5/202614/9/2026
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed…
AnalizadaMedia (6.5)0.43%—Shellhub13/5/202617/6/2026
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device counts — to any caller authenticated by an API Key, for any tenant, regardless of the API Key's own tenant scope. The…
AnalizadaMedia (5.4)0.36%—Shellhub13/5/202617/6/2026
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query parameter and the sort_by query parameter, which are then passed directly as BSON/SQL keys in the database layer without…
AnalizadaMedia (6.5)0.35%—Shellhub13/5/202617/6/2026
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, without verifying that the device belongs to the caller's namespace (tenant). Any authenticated user (JWT or API Key) who knows or can guess a device UID can read device…
AnalizadaMedia (6.5)0.35%—Shellhub13/5/202617/6/2026
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without scoping by the caller's tenant. An authenticated user can read session records (SSH username, device UID, remote IP, terminal type, authenticated flag, timestamps)…
AplazadaAlta (8.4)0.26%—Juno Network JunoclawlAIJuno Network Plugin ShellAI12/5/202617/6/2026
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check could be bypassed by adversarial argument constructions, allowing unauthorized command execution on the host when combined with the companion advisory. Pre-patch, the…
AplazadaAlta (8.4)0.22%—Juno Network JunoclawfastaioAIJuno Network Plugin ShellAI12/5/202617/6/2026
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell's parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command…
AnalizadaCrítica (9.6)0.86%—Microsoft Azure Cloud Shell7/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
ModificadaAlta (7.5)2.3%—Microsoft .netMicrosoft Powershell14/4/202615/7/2026
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)0.47%—Microsoft Powershell14/4/202617/6/2026
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaMedia (6.9)0.22%—Ftpshell Server30/3/202617/6/2026
FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP…
AnalizadaAlta (8.6)0.21%—Ftpshell Server22/3/202617/6/2026
FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and…
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Cloud Shell19/3/202617/6/2026
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.3)0.38%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service…
AnalizadaMedia (5.5)0.40%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a…
ModificadaMedia (6.5)0.22%—Ironmansoftware Powershell Universal27/2/202617/6/2026
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials