Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.87%—Taklaxbr ZAI Shell9/2/202617/6/2026
ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this port using a simple socket script. An…
AnalizadaMedia (6.8)0.10%—Icinga Powershell Framework29/1/202617/6/2026
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of…
AnalizadaMedia (6.1)0.18%—Ironmansoftware Powershell Universal7/1/202617/6/2026
Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.
AnalizadaMedia (6.5)0.97%—Sonirico Mcp-shell7/1/202617/6/2026
A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.
AnalizadaCrítica (9.1)0.42%—Cashu Nutshell8/12/202517/6/2026
NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary data.
AplazadaAlta (8.3)0.19%—Allterco Shelly PRO 3EMAI19/11/202517/6/2026
Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.
AplazadaAlta (8.3)0.40%—Shelly PRO 4PMAI19/11/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.
AnalizadaAlta (7.3)0.48%—Microsoft PowershellMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1314/10/202517/6/2026
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
AplazadaCrítica (9.3)0.67%—Netsarang Xmanager EnterpriseAINetsarang XmanagerAINetsarang XshellAINetsarang XftpAI+19/10/202517/6/2026
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a…
AnalizadaAlta (7)0.33%—Microsoft PowershellMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+99/9/202517/6/2026
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.1%—Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell13/6/202517/6/2026
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.3)1.0%—Tauri Plugin-shell2/4/202517/6/2026
The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be…
AnalizadaAlta (8.6)2.4%⚠ Explotación activaReviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+219/3/202517/6/2026
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be…
AplazadaMedia (6.5)0.27%—Shellbot Easy Image DisplayAI11/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Image Display easy-image-display allows Stored XSS.This issue affects Easy Image Display: from n/a through <= 1.2.5.
AnalizadaAlta (8.8)0.23%—Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell10/2/202517/6/2026
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and…
AnalizadaAlta (7.5)1.7%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/1/202517/6/2026
.NET Remote Code Execution Vulnerability
AplazadaAlta (8.8)0.44%—Ironman Powershell UniversalAI27/10/202417/6/2026
Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.
AplazadaAlta (7.5)0.45%—Com.home.shellyAI11/10/20245/7/2026
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
AplazadaAlta (7.2)1.1%—SSH Captive Command ShellAI26/7/202417/6/2026
A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
AplazadaMedia (6.5)0.34%—Gnome ShellAI28/5/202417/6/2026
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts…
AnalizadaMedia (6.3)1.2%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/5/202417/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
ModificadaAlta (7.3)2.5%—Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 20229/4/202417/6/2026
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
AnalizadaAlta (7.5)3.0%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+412/3/202417/6/2026
Microsoft QUIC Denial of Service Vulnerability
AnalizadaAlta (7.5)3.1%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202212/3/202417/6/2026
.NET and Visual Studio Denial of Service Vulnerability
ModificadaMedia (5.3)0.47%—Shellcreeper F(x) Private Site12/3/202417/6/2026
The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin.