Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Gajshield Data Security Firewall Firmware | 27/4/2023 | 17/6/2026 | This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote… | |
| Modificada | Alta (7.8) | 0.28% | — | Flexera Revenera Installshield | 29/3/2023 | 17/6/2026 | A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action. | |
| Modificada | Media (5.9) | 0.52% | — | Codeigniter Shield | 13/3/2023 | 17/6/2026 | CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefore, they should be… | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check… | |
| Modificada | Alta (7.4) | 60% | — | OpensslStormshield Management CenterStormshield Network Security | 8/2/2023 | 17/6/2026 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by… | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does… | |
| Modificada | Alta (7.5) | 4.5% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new… | |
| Modificada | Alta (7.5) | 20% | — | OpensslStormshield Network Security | 8/2/2023 | 17/6/2026 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is… | |
| Modificada | Media (5.9) | 16% | 💥 PoC | OpensslStormshield Endpoint SecurityStormshield SslvpnStormshield Network Security | 8/2/2023 | 17/6/2026 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The… | |
| Modificada | Crítica (10) | 0.43% | — | Avast Script Shield | 8/12/2022 | 17/6/2026 | The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component. | |
| Modificada | Alta (7.5) | 1.8% | — | StrongswanCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 31/10/2022 | 17/6/2026 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing… | |
| Modificada | Alta (7.8) | 0.17% | — | Siemens Coreshield One-way Gateway | 13/9/2022 | 17/6/2026 | A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator. | |
| Modificada | Alta (7.5) | 0.75% | — | Stormshield Network Security | 24/8/2022 | 17/6/2026 | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS. | |
| Modificada | Alta (8.8) | 0.59% | — | CodeigniterCodeigniter Shield | 12/8/2022 | 17/6/2026 | Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Media (6.5) | 70% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 82% | — | LlhttpNodejs Node.jsDebian LinuxStormshield Management Center | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 46% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Alta (7.5) | 0.99% | — | Stormshield Network Security | 12/5/2022 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash. | |
| Modificada | Alta (7.5) | 0.93% | — | Stormshield Network Security | 15/3/2022 | 17/6/2026 | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all network traffic, making the firewall… | |
| Modificada | Media (4.8) | 0.60% | — | Getshieldsecurity Shield Security | 21/2/2022 | 17/6/2026 | The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Media (5.8) | 0.92% | — | Stormshield Network Security | 10/2/2022 | 17/6/2026 | Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component. | |
| Modificada | Media (6.5) | 0.41% | — | Stormshield Network Security | 10/2/2022 | 17/6/2026 | Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service. |