Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Osgeo Shapelib17/10/202217/6/2026
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
ModificadaMedia (4.3)0.36%—Shapedplugin Product Slider FOR Woocommerce22/8/202217/6/2026
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.
ModificadaCrítica (9.8)1.1%—Codexshaper WP Oauth2 Server22/7/202217/6/2026
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
ModificadaAlta (8.1)1.0%—Shapedplugin Logo Carousel21/12/202117/6/2026
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
ModificadaMedia (5.4)0.60%—Shapedplugin Logo Carousel21/12/202117/6/2026
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)2.5%—Shapeshift Keepkey Firmware6/5/202117/6/2026
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely…
ModificadaAlta (7.5)0.78%—Shapeshift Keepkey Firmware6/12/201917/6/2026
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This…
ModificadaMedia (5.4)1.1%—Shapepress WP Dsgvo Tools29/8/201917/6/2026
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
ModificadaBaja (2.4)0.35%—Shapeshift Keepkey Firmware10/8/201917/6/2026
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this…
ModificadaAlta (7.5)1.1%—Shapeshift Keepkey Firmware14/3/201817/6/2026
Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
ModificadaAlta (8.1)1.1%—Blue Coat Packetshaper S-series12/7/201617/6/2026
The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters.
ModificadaMedia (5.4)0.27%—Shape IM+9/9/201417/6/2026
The IM+ (aka de.shapeservices.impluslite) application 6.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Mirror Photo & Shape Project Mirror Photo & Shape9/9/201417/6/2026
The mirror photo shape (aka com.baiwang.styleinstamirror) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.97%💥 ExploitShape5 Bridge OF Hope Template9/6/201016/6/2026
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
ModificadaMedia (5.1)2.0%💥 ExploitVisualshapers Ezcontents24/8/200916/6/2026
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.
ModificadaMedia (5.1)7.0%💥 ExploitVisualshapers Ezcontents24/8/200916/6/2026
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage, and (5) language_home parameters to…
ModificadaAlta (7.5)1.00%💥 ExploitVisualshapers Ezcontents9/5/200816/6/2026
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.
ModificadaMedia (4.3)1.5%💥 ExploitPacketeer PacketshaperPacketeer Policycenter27/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrary component, which triggers injection into an Error Report page.
ModificadaMedia (5)7.3%💥 ExploitPacketeer Packetshaper11/6/200716/6/2026
rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.
ModificadaAlta (7.5)1.6%—Packeteer Packetshaper21/5/200716/6/2026
Packeteer PacketShaper uses fixed increments in TCP initial sequence number (ISN) values, which allows remote attackers to predict the ISN value, and perform session hijacking or disruption.
ModificadaMedia (4.9)0.43%—Shape Services IM+ Mobile Instant Messenger7/9/200616/6/2026
Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.
ModificadaMedia (4.3)2.1%💥 ExploitVisualshapers Ezcontents31/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter.
ModificadaAlta (7.5)8.1%💥 ExploitVisualshapers Ezcontents31/8/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a) diary/event_list.php, (b) gallery/gallery_summary.php, (c)…
ModificadaAlta (7.5)1.8%💥 ExploitVisualshapers Ezcontents31/8/200616/6/2026
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter.
ModificadaAlta (7.5)2.4%💥 ExploitVisualshapers Ezcontents3/3/200416/6/2026
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version…
Orbitaley — Vulnerabilidades