Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.2)0.24%—Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+12/12/202526/8/2026
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board.
ModificadaCrítica (9.8)0.67%—Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+12/12/202526/8/2026
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
ModificadaMedia (6.8)0.32%—Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+12/12/202526/8/2026
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the…
ModificadaCrítica (9.8)0.90%—Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+12/12/202526/8/2026
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving…
AplazadaMedia (5.6)0.15%—Revenera InstallshieldAI7/11/202517/6/2026
Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The…
AplazadaAlta (7.3)0.13%—Revenera InstallshieldAI29/10/20251/10/2026
Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the MPR.dll may get loaded from an insecure location and can result in a privilege escalation. The issue has been fixed in versions 2023 R2 and…
AnalizadaAlta (7.5)0.34%—Stormshield Network Security25/9/202517/6/2026
An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.
AplazadaCrítica (9.8)0.66%—Voltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system…
AplazadaCrítica (10)0.80%—Voltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code…
AnalizadaBaja (1.3)0.48%—Totalwebshield Total Webshield9/8/202517/6/2026
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack remotely. The…
AplazadaBaja (2.3)0.32%—Hotspot Shield VPN ClientAI30/6/202517/6/2026
Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when accessing third-party web applications through the VPN tunnel. Although such applications do not present this vulnerability per se, the use of the tunnel, together with a forged Host header, can cause…
AplazadaMedia (6.1)0.13%—Link ShieldAI13/6/202517/6/2026
The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing or incorrect nonce validation on the link_shield_menu_options() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
AplazadaAlta (7.3)0.14%—InstallshieldAI12/6/202517/6/2026
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this issue.
AplazadaAlta (7.1)0.38%—Jose Conti Link ShieldAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Conti Link Shield link-shield allows Stored XSS.This issue affects Link Shield: from n/a through <= 0.5.4.
AplazadaAlta (7.3)0.30%—Stormshield Network SecurityAI1/4/202517/6/2026
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall.
AplazadaAlta (8.5)0.17%—Revenera InstallshieldAI30/1/202517/6/2026
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these…
AnalizadaCrítica (9.8)0.36%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
AnalizadaCrítica (9.8)0.36%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
AnalizadaCrítica (9.8)0.42%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
AplazadaAlta (8.8)1.00%—Shields.ioAI26/9/202417/6/2026
Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using version < `server-2024-09-25` are vulnerable to a remote execution vulnerability via the JSONPath library used by the Dynamic JSON/Toml/Yaml badges. This…
AnalizadaMedia (6.1)1.6%—Getshieldsecurity Shield Security26/8/202417/6/2026
The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (4.2)0.20%—Stormshield Network SecurityAI15/7/202417/6/2026
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2.
AplazadaMedia (4.2)0.17%—Stormshield Network SecurityAI15/7/202417/6/2026
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the…
AplazadaMedia (4.3)0.22%—Getshieldsecurity Shield SecurityAI2/6/202417/6/2026
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (7.5)0.31%—Kindspells Astro-shield4/4/202417/6/2026
Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 of Astro-Shield allow bypass to the allow-lists for cross-origin resources by introducing valid `integrity` attributes to the injected code.…