Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Agoric Realms-shim10/1/202217/6/2026
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
ModificadaMedia (5.4)0.53%—Shimo Document22/11/202117/6/2026
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.
ModificadaAlta (7.1)0.39%—Shimovpn Shimo VPN17/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug.
ModificadaAlta (7.8)0.68%—Shimovpn Shimo VPN17/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere on the system. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access…
ModificadaAlta (7.8)0.68%—Shimovpn Shimo VPN17/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit.
ModificadaMedia (5.5)0.38%—Shimovpn Shimo VPN17/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privileged process on the system. An attacker would need local access to the machine for a successful exploit.
ModificadaAlta (7.8)0.44%—Shimovpn Shimo VPN15/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug.
ModificadaAlta (7.8)0.42%—Shimovpn Shimo VPN15/4/201917/6/2026
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their privileges to root. An attacker would…
ModificadaAlta (8.1)2.7%—Haxeshim Project Haxeshim4/6/201817/6/2026
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in…
ModificadaAlta (8.6)35%—Microsoft Windows Host Compute Service Shim2/5/201817/6/2026
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.
ModificadaMedia (6.1)0.84%—Shimmie2 Project Shimmie220/2/201817/6/2026
Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.
ModificadaCrítica (9.8)1.5%—Mailbutler Shimo7/2/201817/6/2026
In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.
ModificadaMedia (5.3)3.5%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ModificadaAlta (7.3)4.2%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ModificadaAlta (7.5)17%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3…
ModificadaMedia (6.1)0.76%—Shishnet Shimmie15/3/201717/6/2026
An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
ModificadaMedia (6.5)1.7%—Network Applied Communication Laboratory Shimane Prefecture CMS11/10/201517/6/2026
SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (2.1)0.44%—Shim Project Shim31/10/201417/6/2026
The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors.
ModificadaAlta (7.5)2.7%—Redhat Shim22/10/201417/6/2026
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
ModificadaAlta (7.5)5.2%—Redhat Shim22/10/201417/6/2026
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
ModificadaMedia (5)2.7%—Redhat Shim22/10/201417/6/2026
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
ModificadaMedia (5.4)0.27%—Netjapan Tsushima Travel Guide23/9/201417/6/2026
The Tsushima Travel Guide (aka com.netjapan.ntsushima) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)4.2%—Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+727/4/201216/6/2026
Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,…
ModificadaAlta (7.5)1.5%—Mawashimono Nikki1/12/201116/6/2026
Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors.
ModificadaAlta (7.5)2.1%—Mawashimono Nikki30/11/201116/6/2026
HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."