Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.59% | — | Kindspells Astro-shield | 28/3/2024 | 17/6/2026 | Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation… | |
| Analizada | Media (4.8) | 0.41% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious… | |
| Analizada | Alta (7.3) | 0.51% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage… | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Getshieldsecurity Shield Security | 5/2/2024 | 17/6/2026 | The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server,… | |
| Modificada | Media (6.1) | 0.33% | — | Getshieldsecurity Shield Security | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shield Security Shield Security – Smart Bot Blocking & Intrusion Prevention Security allows Stored XSS.This issue affects Shield Security – Smart Bot Blocking & Intrusion Prevention Security: from n/a through 18.5.7. | |
| Modificada | Media (5.5) | 0.14% | — | Flexera Installshield | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders. | |
| Modificada | Alta (7.5) | 0.29% | — | Stormshield Network Security | 26/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the… | |
| Modificada | Alta (7.5) | 0.53% | — | Stormshield Network Security | 25/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible. | |
| Modificada | Media (6.5) | 0.29% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine. | |
| Modificada | Media (5.3) | 0.40% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands. | |
| Modificada | Media (6.5) | 0.63% | — | Codeigniter Shield | 24/11/2023 | 17/6/2026 | CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a… | |
| Modificada | Media (6.5) | 0.28% | — | Codeigniter Shield | 24/11/2023 | 17/6/2026 | CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the data in the database, they could use the… | |
| Modificada | Crítica (9.8) | 1.3% | — | Kloudq TOR Loco MINKloudq TOR Equip GatewayKloudq TOR ShieldKloudq TOR Lenz | 15/11/2023 | 17/6/2026 | An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component. | |
| Modificada | Alta (7.5) | 0.62% | — | Stormshield Network Security | 28/8/2023 | 17/6/2026 | ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. | |
| Modificada | Media (5.3) | 0.29% | — | Stormshield SSL VPN Client | 28/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. | |
| Modificada | Alta (7.8) | 0.19% | — | Stormshield SSL VPN Client | 25/8/2023 | 17/6/2026 | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions. | |
| Modificada | Media (4.8) | 0.47% | — | Stormshield Network Security | 25/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious… | |
| Modificada | Alta (7.8) | 0.19% | — | Stormshield SSL VPN Client | 5/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. | |
| Modificada | Media (4.3) | 0.39% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators. | |
| Modificada | Media (5.5) | 0.19% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges. | |
| Modificada | Media (4.3) | 0.55% | — | Getshieldsecurity Shield Security | 9/6/2023 | 17/6/2026 | The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site… | |
| Modificada | Media (6.1) | 93% | — | Getshieldsecurity Shield Security | 9/6/2023 | 17/6/2026 | The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Modificada | Media (4.3) | 0.41% | — | Stormshield Endpoint Security | 31/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | |
| Modificada | Media (5.5) | 0.15% | — | Stormshield Endpoint Security | 30/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | |
| Modificada | Alta (7.5) | 0.68% | — | Shieldstore Project Shieldstore | 9/5/2023 | 9/7/2026 | A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system. |