Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.82% | — | Microsoft Powershellget | 16/10/2020 | 17/6/2026 | <p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited this vulnerability could bypass WDAC (Windows Defender Application Control) policy and execute arbitrary code on a policy locked-down machine.</p> <p>An attacker must have administrator privileges… | |
| Modificada | Alta (7.8) | 0.40% | — | NEC Infocage Siteshell | 6/10/2020 | 17/6/2026 | InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision… | |
| Modificada | Media (6.5) | 3.2% | — | Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+6 | 15/9/2020 | 17/6/2026 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or… | |
| Modificada | Media (6.7) | 6.6% | — | Microsoft PowershellMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 11/9/2020 | 17/6/2026 | <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an… | |
| Modificada | Media (4.3) | 0.55% | — | Gnome-shellCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 11/8/2020 | 17/6/2026 | An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment… | |
| Modificada | Alta (7.5) | 6.3% | — | Microsoft .netMicrosoft .net CoreMicrosoft .net FrameworkMicrosoft Visual Studio 2017+3 | 21/5/2020 | 19/8/2026 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without… | |
| Modificada | Media (5.5) | 0.23% | — | Windowshello Project Windowshello | 14/4/2020 | 17/6/2026 | The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be… | |
| Modificada | Alta (7) | 0.29% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name. | |
| Modificada | Crítica (9.8) | 3.2% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt. | |
| Modificada | Alta (7) | 0.31% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name. | |
| Modificada | Alta (8.8) | 2.0% | — | GitlabGitlab-shell | 28/1/2020 | 16/6/2026 | The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories. | |
| Modificada | Media (6.5) | 1.9% | — | GitlabGitlab-shell | 28/1/2020 | 16/6/2026 | The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into… | |
| Modificada | Media (5.5) | 0.43% | — | Mysecureshell Project Mysecureshell | 23/1/2020 | 16/6/2026 | mysecureshell 1.31: Local Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 0.44% | — | Mysecureshell Project Mysecureshell | 23/1/2020 | 16/6/2026 | MySecureShell 1.31 has a Local Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 4.6% | — | Php-shellcommand Project Php-shellcommand | 30/12/2019 | 17/6/2026 | php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 5.3% | — | Microsoft .net CoreMicrosoft Powershell Core | 11/9/2019 | 17/6/2026 | A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. | |
| Modificada | Crítica (9.8) | 90% | — | Zeroshell | 19/7/2019 | 17/6/2026 | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. | |
| Modificada | Media (4.1) | 1.1% | — | Microsoft Powershell Core | 19/7/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | |
| Modificada | Alta (7.5) | 6.0% | — | Shellinabox Project Shellinabox | 21/3/2019 | 17/6/2026 | libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down. | |
| Modificada | Media (5.9) | 4.5% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017Microsoft .net Framework | 5/3/2019 | 17/6/2026 | A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632. | |
| Modificada | Media (4.3) | 0.50% | — | Gnome-shellOpensuse LeapCanonical Ubuntu Linux | 6/2/2019 | 17/6/2026 | It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+5 | 14/11/2018 | 17/6/2026 | A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1,… |