Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.28% | — | Nvidia Jetson LinuxNvidia Shield Experience | 11/8/2021 | 17/6/2026 | NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVMAP_IOC_WRITE* paths, where improper access controls may lead to code execution, complete denial of service, and seriously compromised integrity of all system components. | |
| Modificada | Alta (7.8) | 0.26% | — | Nvidia Jetson LinuxNvidia Shield Experience | 11/8/2021 | 17/6/2026 | NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on the system. | |
| Modificada | Media (6.7) | 0.25% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones. | |
| Modificada | Baja (3.5) | 0.33% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies. | |
| Modificada | Media (5.7) | 0.61% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.7) | 0.46% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.7) | 0.49% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.2) | 0.30% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies. | |
| Modificada | Alta (7.3) | 0.33% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Alta (7.5) | 0.94% | — | Stormshield Network Security | 1/7/2021 | 17/6/2026 | An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. | |
| Modificada | Alta (7.5) | 0.99% | — | Stormshield Network SecurityStormshield Network Security | 6/5/2021 | 17/6/2026 | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service. | |
| Modificada | Media (5.5) | 1.3% | — | Netasq Project NetasqStormshield Network SecurityClamav | 19/3/2021 | 17/6/2026 | The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1. | |
| Modificada | Media (6.1) | 1.1% | — | Terryl WP Shieldon | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation. | |
| Modificada | Media (5.3) | 1.1% | — | Stormshield Network Security | 2/3/2021 | 17/6/2026 | A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to… | |
| Modificada | Media (5.9) | 1.0% | — | Cira Canadian Shield | 23/2/2021 | 17/6/2026 | The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation. | |
| Modificada | Alta (7.2) | 4.5% | — | Netshieldcorp Nano 25 Firmware | 22/2/2021 | 17/6/2026 | On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely. | |
| Modificada | Media (5.3) | 1.1% | — | Deepnetsecurity Dualshield | 16/2/2021 | 17/6/2026 | DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an "unknown username" error message. | |
| Modificada | Alta (8.8) | 1.2% | — | ADT Lifeshield DIY HD Video Doorbell Firmware | 2/2/2021 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior… | |
| Modificada | Media (5.3) | 1.2% | — | Godaddy Node-config-shield | 27/1/2021 | 17/6/2026 | scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data | |
| Modificada | Media (6.1) | 0.33% | — | Nvidia Shield ExperienceNvidia Linux FOR Tegra | 20/1/2021 | 17/6/2026 | NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVHost function, which may lead to abnormal reboot due to a null pointer reference, causing data loss. | |
| Modificada | Alta (7.8) | 0.37% | — | Nvidia Shield Experience | 20/1/2021 | 17/6/2026 | NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVDEC component, in which an attacker can read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service or escalation of privileges. | |
| Modificada | Media (6.8) | 0.38% | — | Nvidia Shield Experience | 20/1/2021 | 17/6/2026 | NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the implementation of the RPMB command status, in which an attacker can write to the Write Protect Configuration Block, which may lead to denial of service or escalation of privileges. | |
| Modificada | Alta (7.5) | 2.0% | — | MPD Project MPDStormshield Network Security | 6/10/2020 | 17/6/2026 | The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition. | |
| Modificada | Crítica (9.8) | 3.0% | — | MPD Project MPDStormshield Network Security | 6/10/2020 | 17/6/2026 | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption). | |
| Modificada | Alta (7.8) | 0.38% | — | Pango Hotspot Shield | 24/9/2020 | 17/6/2026 | Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link… |