Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.65%—Microsoft PowershellMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 8.1+615/4/202217/6/2026
PowerShell Elevation of Privilege Vulnerability
ModificadaMedia (6.5)0.48%—Netsarang Xshell31/3/202217/6/2026
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
ModificadaAlta (7.8)1.5%—Fishshell FishFedoraproject FedoraDebian Linux14/3/202217/6/2026
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory…
ModificadaMedia (6.3)1.6%—Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+29/3/202217/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.20%—Gnome-shellCentos Stream18/2/202217/6/2026
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked…
ModificadaAlta (7.1)0.43%—Shelljs Project Shelljs11/1/202217/6/2026
shelljs is vulnerable to Improper Privilege Management
ModificadaAlta (7.5)1.2%—Ftpshell Server17/12/202117/6/2026
A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).
ModificadaMedia (5.5)2.3%—Microsoft Powershell15/12/202117/6/2026
Microsoft PowerShell Spoofing Vulnerability
ModificadaCrítica (9.8)4.2%—Shell-quote Project Shell-quote21/10/202117/6/2026
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject…
ModificadaMedia (5.7)20%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 201913/10/202117/6/2026
.NET Core and Visual Studio Information Disclosure Vulnerability
ModificadaAlta (7.5)0.96%—Netsarang Xshell7/10/202117/6/2026
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.
ModificadaCrítica (9.8)0.60%—Handysoft Hshell9/9/202117/6/2026
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
ModificadaMedia (5.3)0.79%—Netsarang Xshell15/8/202117/6/2026
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
ModificadaMedia (5.5)1.5%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+112/8/202110/8/2026
.NET Core and Visual Studio Information Disclosure Vulnerability
ModificadaAlta (7.5)3.9%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+112/8/202110/8/2026
.NET Core and Visual Studio Denial of Service Vulnerability
ModificadaMedia (6.1)0.24%—Theforeman Smart Proxy Shell Hooks12/5/202117/6/2026
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on…
ModificadaMedia (4.4)0.92%—Yubico Yubihsm-shell10/5/202117/6/2026
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an integer overflow, which causes…
ModificadaCrítica (9.8)1.8%—Shellcheck Project Shellcheck18/3/202117/6/2026
The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
ModificadaMedia (4.4)1.6%—Yubico Yubihsm-shell4/3/202117/6/2026
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on…
ModificadaCrítica (9.8)30%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2019+125/2/202117/6/2026
.NET Core Remote Code Execution Vulnerability
ModificadaMedia (6.5)3.3%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+125/2/202117/6/2026
.NET Core and Visual Studio Denial of Service Vulnerability
ModificadaMedia (6.1)0.70%—Quali Cloudshell17/1/202117/6/2026
An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.
ModificadaCrítica (9.8)40%—Zeroshell30/11/202017/6/2026
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
ModificadaAlta (7.5)1.8%—Yubico Yubihsm-shellFedoraproject Fedora19/10/202017/6/2026
An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a…
ModificadaAlta (7.5)1.8%—Yubico Yubihsm-shellFedoraproject Fedora19/10/202017/6/2026
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a…