Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.87% | — | Taklaxbr ZAI Shell | 9/2/2026 | 17/6/2026 | ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this port using a simple socket script. An… | |
| Analizada | Media (6.8) | 0.10% | — | Icinga Powershell Framework | 29/1/2026 | 17/6/2026 | The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of… | |
| Analizada | Media (6.1) | 0.18% | — | Ironmansoftware Powershell Universal | 7/1/2026 | 17/6/2026 | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. | |
| Analizada | Media (6.5) | 0.97% | — | Sonirico Mcp-shell | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string. | |
| Analizada | Crítica (9.1) | 0.42% | — | Cashu Nutshell | 8/12/2025 | 17/6/2026 | NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary data. | |
| Aplazada | Alta (8.3) | 0.19% | — | Allterco Shelly PRO 3EMAI | 19/11/2025 | 17/6/2026 | Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers. | |
| Aplazada | Alta (8.3) | 0.40% | — | Shelly PRO 4PMAI | 19/11/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network. | |
| Analizada | Alta (7.3) | 0.48% | — | Microsoft PowershellMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+13 | 14/10/2025 | 17/6/2026 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Crítica (9.3) | 0.67% | — | Netsarang Xmanager EnterpriseAINetsarang XmanagerAINetsarang XshellAINetsarang XftpAI+1 | 9/10/2025 | 17/6/2026 | NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a… | |
| Analizada | Alta (7) | 0.33% | — | Microsoft PowershellMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+9 | 9/9/2025 | 17/6/2026 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell | 13/6/2025 | 17/6/2026 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 1.0% | — | Tauri Plugin-shell | 2/4/2025 | 17/6/2026 | The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be… | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Aplazada | Media (6.5) | 0.27% | — | Shellbot Easy Image DisplayAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Image Display easy-image-display allows Stored XSS.This issue affects Easy Image Display: from n/a through <= 1.2.5. | |
| Analizada | Alta (8.8) | 0.23% | — | Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell | 10/2/2025 | 17/6/2026 | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and… | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | .NET Remote Code Execution Vulnerability | |
| Aplazada | Alta (8.8) | 0.44% | — | Ironman Powershell UniversalAI | 27/10/2024 | 17/6/2026 | Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information. | |
| Aplazada | Alta (7.5) | 0.45% | — | Com.home.shellyAI | 11/10/2024 | 5/7/2026 | An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process | |
| Aplazada | Alta (7.2) | 1.1% | — | SSH Captive Command ShellAI | 26/7/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads. | |
| Aplazada | Media (6.5) | 0.34% | — | Gnome ShellAI | 28/5/2024 | 17/6/2026 | In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts… | |
| Analizada | Media (6.3) | 1.2% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/5/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 2.5% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 9/4/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 3.0% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+4 | 12/3/2024 | 17/6/2026 | Microsoft QUIC Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 3.1% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 12/3/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (5.3) | 0.47% | — | Shellcreeper F(x) Private Site | 12/3/2024 | 17/6/2026 | The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin. |