Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2563▼ 389 respecto a la semana anterior
Críticas / altas1328▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 468 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.11% | — | Shelly TRV Firmware | 23/1/2024 | 17/6/2026 | Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password. | |
| Modificada | Media (5.4) | 0.15% | — | Shelly TRV Firmware | 23/1/2024 | 17/6/2026 | Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware. | |
| Modificada | Crítica (9.8) | 2.8% | — | Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net | 9/1/2024 | 17/6/2026 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (6.6) | 0.47% | — | Fishshell Fish | 5/12/2023 | 17/6/2026 | fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe… | |
| Modificada | Alta (8.8) | 2.1% | — | Ironmansoftware Powershell Universal | 23/11/2023 | 17/6/2026 | The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1. | |
| Modificada | Media (6.5) | 1.4% | — | Microsoft Powershell | 20/11/2023 | 17/6/2026 | PowerShell Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 0.30% | — | Gnome-shellFedoraproject Fedora | 22/9/2023 | 17/6/2026 | A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. | |
| Modificada | Media (5.3) | 4.7% | — | Shelly PRO 4PM Firmware | 2/8/2023 | 17/6/2026 | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload. | |
| Modificada | Alta (7.8) | 0.26% | — | Psappdeploytoolkit Powershell APP Deployment Toolkit | 1/8/2023 | 17/6/2026 | In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft .netMicrosoft PowershellFedoraproject Fedora | 10/1/2023 | 17/6/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft PowershellMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11+8 | 13/12/2022 | 17/6/2026 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.5) | 61% | — | Microsoft PowershellMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 7+7 | 13/12/2022 | 17/6/2026 | PowerShell Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.0% | — | Ironmansoftware Powershell Universal | 14/11/2022 | 17/6/2026 | The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to… | |
| Modificada | Alta (8.8) | 0.82% | — | Ironmansoftware Powershell Universal | 14/11/2022 | 17/6/2026 | Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6. | |
| Modificada | Media (5.9) | 2.4% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell | 9/8/2022 | 17/6/2026 | .NET Spoofing Vulnerability | |
| Modificada | Alta (7.5) | 0.62% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext. | |
| Modificada | Alta (7.5) | 1.5% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device. | |
| Modificada | Crítica (9.8) | 1.1% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22). | |
| Modificada | Media (4.2) | 0.23% | — | Oracle Mysql Shell | 19/7/2022 | 17/6/2026 | Vulnerability in the MySQL Shell for VS Code product of Oracle MySQL (component: Shell: GUI). Supported versions that are affected are 1.1.8 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Shell for VS Code executes to compromise MySQL Shell for… | |
| Analizada | Baja (2.5) | 0.50% | — | Oracle Mysql Shell | 19/7/2022 | 22/6/2026 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: General/Core Client). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell.… | |
| Modificada | Alta (8.8) | 1.8% | — | Zeroshell | 11/6/2022 | 17/6/2026 | ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands. | |
| Modificada | Alta (7.5) | 5.7% | — | Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+2 | 10/5/2022 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 32% | — | Vandyke Vshell | 2/5/2022 | 17/6/2026 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | |
| Modificada | Media (5.5) | 0.29% | — | Gnome-shell | 29/4/2022 | 17/6/2026 | Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other… |