Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)86%💥 PoCApache Shiro3/2/202117/6/2026
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
ModificadaCrítica (9.8)8.2%—Apache ShiroDebian Linux5/11/202017/6/2026
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
ModificadaAlta (7.5)44%💥 PoCApache ShiroDebian Linux17/8/202017/6/2026
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
ModificadaCrítica (9.8)24%💥 PoCApache Shiro22/6/202017/6/2026
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
ModificadaCrítica (9.8)23%—Apache ShiroDebian Linux25/3/202017/6/2026
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
ModificadaAlta (7.5)9.1%💥 PoCApache Shiro18/11/201917/6/2026
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
ModificadaAlta (7.5)2.4%—Mrbird Febs-shiro25/12/201817/6/2026
An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a…
ModificadaMedia (5.9)0.95%—Akindo-sushiro Sushiro21/4/201717/6/2026
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
ModificadaAlta (7.5)9.7%—Apache Shiro20/9/201617/6/2026
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitApache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories7/6/201617/6/2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
ModificadaMedia (6.1)1.0%—Shiro8 Category Freearea AdditionShiro8 Itemdetail Freearea Addition28/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in the shiro8 (1) category_freearea_ addition_plugin plugin 1.0 and (2) itemdetail_freearea_ addition_plugin plugin 1.0 for EC-CUBE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)0.93%—Shiromuku Guestbook7/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.6%—Shiromuku BU2 BBS1/2/201517/6/2026
Unrestricted file upload vulnerability in Mrs. Shiromuku Perl CGI shiromuku(bu2)BBS before 2.91 allows remote attackers to execute arbitrary code by uploading an executable file.
ModificadaAlta (7.5)5.5%—Apache Shiro6/10/201417/6/2026
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
ModificadaAlta (7.5)3.5%—Justsystems Sanshiro29/1/201417/6/2026
Unspecified vulnerability in JustSystems Sanshiro 2007 before update 3, 2008 before update 5, 2009 before update 6, and 2010 before update 6, and Sanshiro Viewer before 2.0.2.0, allows remote attackers to execute arbitrary code via a crafted document.
ModificadaMedia (5)55%💥 ExploitApache ShiroJsecurity5/11/201016/6/2026
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
ModificadaMedia (4.3)1.1%—T-okada Shiromuku(fs6)diary21/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in Perl CGI's By Mrs. Shiromuku shiromuku(fs6)DIARY 2.40 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)3.1%—Justsystem HanakoJustsystem Hanako ViewerJustsystem IchitaroJustsystem Ichitaro Lite2+210/12/200616/6/2026
Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields.
ModificadaAlta (10)5.3%—Hiroaki Shirouzu IP Messenger16/6/200316/6/2026
Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.
Orbitaley — Vulnerabilidades