Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.65% | — | Microsoft PowershellMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 8.1+6 | 15/4/2022 | 17/6/2026 | PowerShell Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 0.48% | — | Netsarang Xshell | 31/3/2022 | 17/6/2026 | Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | |
| Modificada | Alta (7.8) | 1.5% | — | Fishshell FishFedoraproject FedoraDebian Linux | 14/3/2022 | 17/6/2026 | fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory… | |
| Modificada | Media (6.3) | 1.6% | — | Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+2 | 9/3/2022 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.20% | — | Gnome-shellCentos Stream | 18/2/2022 | 17/6/2026 | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked… | |
| Modificada | Alta (7.1) | 0.43% | — | Shelljs Project Shelljs | 11/1/2022 | 17/6/2026 | shelljs is vulnerable to Improper Privilege Management | |
| Modificada | Alta (7.5) | 1.2% | — | Ftpshell Server | 17/12/2021 | 17/6/2026 | A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS). | |
| Modificada | Media (5.5) | 2.3% | — | Microsoft Powershell | 15/12/2021 | 17/6/2026 | Microsoft PowerShell Spoofing Vulnerability | |
| Modificada | Crítica (9.8) | 4.2% | — | Shell-quote Project Shell-quote | 21/10/2021 | 17/6/2026 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject… | |
| Modificada | Media (5.7) | 20% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2019 | 13/10/2021 | 17/6/2026 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 0.96% | — | Netsarang Xshell | 7/10/2021 | 17/6/2026 | Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar. | |
| Modificada | Crítica (9.8) | 0.60% | — | Handysoft Hshell | 9/9/2021 | 17/6/2026 | An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | |
| Modificada | Media (5.3) | 0.79% | — | Netsarang Xshell | 15/8/2021 | 17/6/2026 | NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations. | |
| Modificada | Media (5.5) | 1.5% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 12/8/2021 | 10/8/2026 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 3.9% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 12/8/2021 | 10/8/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (6.1) | 0.24% | — | Theforeman Smart Proxy Shell Hooks | 12/5/2021 | 17/6/2026 | An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on… | |
| Modificada | Media (4.4) | 0.92% | — | Yubico Yubihsm-shell | 10/5/2021 | 17/6/2026 | An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an integer overflow, which causes… | |
| Modificada | Crítica (9.8) | 1.8% | — | Shellcheck Project Shellcheck | 18/3/2021 | 17/6/2026 | The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath. | |
| Modificada | Media (4.4) | 1.6% | — | Yubico Yubihsm-shell | 4/3/2021 | 17/6/2026 | An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on… | |
| Modificada | Crítica (9.8) | 30% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2019+1 | 25/2/2021 | 17/6/2026 | .NET Core Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 3.3% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 25/2/2021 | 17/6/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (6.1) | 0.70% | — | Quali Cloudshell | 17/1/2021 | 17/6/2026 | An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page. | |
| Modificada | Crítica (9.8) | 40% | — | Zeroshell | 30/11/2020 | 17/6/2026 | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character. | |
| Modificada | Alta (7.5) | 1.8% | — | Yubico Yubihsm-shellFedoraproject Fedora | 19/10/2020 | 17/6/2026 | An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a… | |
| Modificada | Alta (7.5) | 1.8% | — | Yubico Yubihsm-shellFedoraproject Fedora | 19/10/2020 | 17/6/2026 | An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a… |