Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Osgeo Shapelib | 17/10/2022 | 17/6/2026 | A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc. | |
| Modificada | Media (4.3) | 0.36% | — | Shapedplugin Product Slider FOR Woocommerce | 22/8/2022 | 17/6/2026 | The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codexshaper WP Oauth2 Server | 22/7/2022 | 17/6/2026 | Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. | |
| Modificada | Alta (8.1) | 1.0% | — | Shapedplugin Logo Carousel | 21/12/2021 | 17/6/2026 | The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature | |
| Modificada | Media (5.4) | 0.60% | — | Shapedplugin Logo Carousel | 21/12/2021 | 17/6/2026 | The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 2.5% | — | Shapeshift Keepkey Firmware | 6/5/2021 | 17/6/2026 | Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely… | |
| Modificada | Alta (7.5) | 0.78% | — | Shapeshift Keepkey Firmware | 6/12/2019 | 17/6/2026 | Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This… | |
| Modificada | Media (5.4) | 1.1% | — | Shapepress WP Dsgvo Tools | 29/8/2019 | 17/6/2026 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS. | |
| Modificada | Baja (2.4) | 0.35% | — | Shapeshift Keepkey Firmware | 10/8/2019 | 17/6/2026 | On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this… | |
| Modificada | Alta (7.5) | 1.1% | — | Shapeshift Keepkey Firmware | 14/3/2018 | 17/6/2026 | Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks. | |
| Modificada | Alta (8.1) | 1.1% | — | Blue Coat Packetshaper S-series | 12/7/2016 | 17/6/2026 | The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters. | |
| Modificada | Media (5.4) | 0.27% | — | Shape IM+ | 9/9/2014 | 17/6/2026 | The IM+ (aka de.shapeservices.impluslite) application 6.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mirror Photo & Shape Project Mirror Photo & Shape | 9/9/2014 | 17/6/2026 | The mirror photo shape (aka com.baiwang.styleinstamirror) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Shape5 Bridge OF Hope Template | 9/6/2010 | 16/6/2026 | SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Visualshapers Ezcontents | 24/8/2009 | 16/6/2026 | module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function. | |
| Modificada | Media (5.1) | 7.0% | 💥 Exploit | Visualshapers Ezcontents | 24/8/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage, and (5) language_home parameters to… | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Visualshapers Ezcontents | 9/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Packeteer PacketshaperPacketeer Policycenter | 27/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrary component, which triggers injection into an Error Report page. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Packeteer Packetshaper | 11/6/2007 | 16/6/2026 | rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters. | |
| Modificada | Alta (7.5) | 1.6% | — | Packeteer Packetshaper | 21/5/2007 | 16/6/2026 | Packeteer PacketShaper uses fixed increments in TCP initial sequence number (ISN) values, which allows remote attackers to predict the ISN value, and perform session hijacking or disruption. | |
| Modificada | Media (4.9) | 0.43% | — | Shape Services IM+ Mobile Instant Messenger | 7/9/2006 | 16/6/2026 | Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Visualshapers Ezcontents | 31/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Visualshapers Ezcontents | 31/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a) diary/event_list.php, (b) gallery/gallery_summary.php, (c)… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Visualshapers Ezcontents | 31/8/2006 | 16/6/2026 | SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Visualshapers Ezcontents | 3/3/2004 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version… |