Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.82%—Microsoft Powershellget16/10/202017/6/2026
<p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited this vulnerability could bypass WDAC (Windows Defender Application Control) policy and execute arbitrary code on a policy locked-down machine.</p> <p>An attacker must have administrator privileges…
ModificadaAlta (7.8)0.40%—NEC Infocage Siteshell6/10/202017/6/2026
InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision…
ModificadaMedia (6.5)3.2%—Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+615/9/202017/6/2026
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or…
ModificadaMedia (6.7)6.6%—Microsoft PowershellMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 201911/9/202017/6/2026
<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an…
ModificadaMedia (4.3)0.55%—Gnome-shellCanonical Ubuntu LinuxDebian LinuxOpensuse Leap11/8/202017/6/2026
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment…
ModificadaAlta (7.5)6.3%—Microsoft .netMicrosoft .net CoreMicrosoft .net FrameworkMicrosoft Visual Studio 2017+321/5/202019/8/2026
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without…
ModificadaMedia (5.5)0.23%—Windowshello Project Windowshello14/4/202017/6/2026
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be…
ModificadaAlta (7)0.29%—Fishshell Fish28/1/202017/6/2026
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
ModificadaCrítica (9.8)3.2%—Fishshell Fish28/1/202017/6/2026
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
ModificadaAlta (7)0.31%—Fishshell Fish28/1/202017/6/2026
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
ModificadaAlta (8.8)2.0%—GitlabGitlab-shell28/1/202016/6/2026
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
ModificadaMedia (6.5)1.9%—GitlabGitlab-shell28/1/202016/6/2026
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into…
ModificadaMedia (5.5)0.43%—Mysecureshell Project Mysecureshell23/1/202016/6/2026
mysecureshell 1.31: Local Information Disclosure Vulnerability
ModificadaMedia (5.5)0.44%—Mysecureshell Project Mysecureshell23/1/202016/6/2026
MySecureShell 1.31 has a Local Denial of Service Vulnerability
ModificadaCrítica (9.8)4.6%—Php-shellcommand Project Php-shellcommand30/12/201917/6/2026
php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.5)5.3%—Microsoft .net CoreMicrosoft Powershell Core11/9/201917/6/2026
A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.
ModificadaCrítica (9.8)90%—Zeroshell19/7/201917/6/2026
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
ModificadaMedia (4.1)1.1%—Microsoft Powershell Core19/7/201917/6/2026
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
ModificadaAlta (7.5)6.0%—Shellinabox Project Shellinabox21/3/201917/6/2026
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
ModificadaMedia (5.9)4.5%—Microsoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017Microsoft .net Framework5/3/201917/6/2026
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
ModificadaAlta (7.8)1.3%—Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 20195/3/201917/6/2026
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631.
ModificadaAlta (7.8)1.3%—Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 20195/3/201917/6/2026
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632.
ModificadaAlta (7.8)1.3%—Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 20195/3/201917/6/2026
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
ModificadaMedia (4.3)0.50%—Gnome-shellOpensuse LeapCanonical Ubuntu Linux6/2/201917/6/2026
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
ModificadaAlta (7.8)1.2%—Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+514/11/201817/6/2026
A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1,…