Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 23% | — | Microsoft.powershell.archiveMicrosoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7+6 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008… | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Asp.net CoreMicrosoft Powershell Core | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0. | |
| Modificada | Media (5.5) | 0.75% | — | Microsoft .net FrameworkMicrosoft Powershell CoreMicrosoft .net CoreMicrosoft .net Framework Developer Pack+1 | 11/7/2018 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1,… | |
| Modificada | Crítica (9.8) | 22% | — | Microsoft PowershellMicrosoft Powershell Editor Services | 11/7/2018 | 17/6/2026 | A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension. | |
| Modificada | Crítica (9.8) | 2.3% | — | Shell-quote Project Shell-quote | 31/5/2018 | 17/6/2026 | The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection. | |
| Modificada | Alta (7.5) | 9.1% | — | Microsoft Asp.net CoreMicrosoft Powershell Core | 14/3/2018 | 17/6/2026 | .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability". | |
| Modificada | Crítica (9.8) | 69% | — | Ftpshell Client | 1/3/2018 | 17/6/2026 | An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after this overflow, one can run arbitrary code on the victim machine. This is similar to CVE-2009-3364 and CVE-2017-6465. | |
| Modificada | Alta (7.8) | 0.43% | — | Fishshell FishFedoraproject Fedora | 9/2/2018 | 17/6/2026 | fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER. | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability." | |
| Modificada | Alta (7.5) | 8.9% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765. | |
| Modificada | Media (5.6) | 94% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.4) | 3.0% | — | Quali Cloudshell | 18/8/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Name or (2) Description parameter to RM/Reservation/ReserveNew; the (3) Description parameter to RM/Topology/Update; the (4) Name, (5) Description, (6)… | |
| Modificada | Alta (8.8) | 12% | — | Git-shellOpensuse LeapDebian LinuxCanonical Ubuntu Linux+1 | 1/6/2017 | 17/6/2026 | git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character. | |
| Modificada | Alta (8.1) | 3.0% | — | Gnome-shell | 27/4/2017 | 17/6/2026 | gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what… | |
| Modificada | Crítica (9.9) | 5.0% | — | Lshell Project Lshell | 24/4/2017 | 17/6/2026 | lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. | |
| Modificada | Crítica (9.9) | 5.1% | — | Lshell Project Lshell | 24/4/2017 | 17/6/2026 | lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. | |
| Modificada | Crítica (9.8) | 50% | — | Ftpshell Client | 10/3/2017 | 17/6/2026 | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation. | |
| Modificada | Alta (8.1) | 70% | — | BeanshellDebian LinuxCanonical Ubuntu Linux | 7/4/2016 | 17/6/2026 | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler. | |
| Modificada | Alta (7.4) | 2.0% | — | Fedoraproject FedoraShellinabox Project Shellinabox | 12/1/2016 | 17/6/2026 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL. | |
| Modificada | Alta (7.2) | 0.47% | — | Gnome-shellRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 25/12/2014 | 17/6/2026 | GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock… | |
| Modificada | Media (6.5) | 1.5% | — | GitlabGitlab-shell | 13/5/2014 | 16/6/2026 | The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL. | |
| Modificada | Media (6.5) | 42% | — | GitlabGitlab-shell | 13/5/2014 | 16/6/2026 | The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key. | |
| Modificada | Media (6.8) | 2.1% | — | GitlabGitlab-shell | 12/5/2014 | 16/6/2026 | GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH. | |
| Modificada | Media (6.9) | 0.35% | — | Fishshell Fish | 2/5/2014 | 17/6/2026 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions. | |
| Modificada | Media (4.6) | 0.41% | — | Gnome-shell | 29/4/2014 | 17/6/2026 | The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation. |