Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Agoric Realms-shim | 10/1/2022 | 17/6/2026 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | |
| Modificada | Media (5.4) | 0.53% | — | Shimo Document | 22/11/2021 | 17/6/2026 | Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field. | |
| Modificada | Alta (7.1) | 0.39% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug. | |
| Modificada | Alta (7.8) | 0.68% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere on the system. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access… | |
| Modificada | Alta (7.8) | 0.68% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit. | |
| Modificada | Media (5.5) | 0.38% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privileged process on the system. An attacker would need local access to the machine for a successful exploit. | |
| Modificada | Alta (7.8) | 0.44% | — | Shimovpn Shimo VPN | 15/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug. | |
| Modificada | Alta (7.8) | 0.42% | — | Shimovpn Shimo VPN | 15/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their privileges to root. An attacker would… | |
| Modificada | Alta (8.1) | 2.7% | — | Haxeshim Project Haxeshim | 4/6/2018 | 17/6/2026 | haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in… | |
| Modificada | Alta (8.6) | 35% | — | Microsoft Windows Host Compute Service Shim | 2/5/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute. | |
| Modificada | Media (6.1) | 0.84% | — | Shimmie2 Project Shimmie2 | 20/2/2018 | 17/6/2026 | Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mailbutler Shimo | 7/2/2018 | 17/6/2026 | In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root. | |
| Modificada | Media (5.3) | 3.5% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.3) | 4.2% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3… | |
| Modificada | Media (6.1) | 0.76% | — | Shishnet Shimmie | 15/3/2017 | 17/6/2026 | An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |
| Modificada | Media (6.5) | 1.7% | — | Network Applied Communication Laboratory Shimane Prefecture CMS | 11/10/2015 | 17/6/2026 | SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.44% | — | Shim Project Shim | 31/10/2014 | 17/6/2026 | The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Redhat Shim | 22/10/2014 | 17/6/2026 | Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption. | |
| Modificada | Alta (7.5) | 5.2% | — | Redhat Shim | 22/10/2014 | 17/6/2026 | Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option." | |
| Modificada | Media (5) | 2.7% | — | Redhat Shim | 22/10/2014 | 17/6/2026 | Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet. | |
| Modificada | Media (5.4) | 0.27% | — | Netjapan Tsushima Travel Guide | 23/9/2014 | 17/6/2026 | The Tsushima Travel Guide (aka com.netjapan.ntsushima) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+7 | 27/4/2012 | 16/6/2026 | Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,… | |
| Modificada | Alta (7.5) | 1.5% | — | Mawashimono Nikki | 1/12/2011 | 16/6/2026 | Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Mawashimono Nikki | 30/11/2011 | 16/6/2026 | HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." |