Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.94%—Stormshield Network Security13/4/202017/6/2026
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.
ModificadaAlta (7.5)1.3%—PAM Shield Project PAM ShieldDebian Linux21/11/201916/6/2026
pam_shield before 0.9.4: Default configuration does not perform protective action
ModificadaAlta (7.8)0.67%💥 PoCNvidia Shield Experience9/10/201917/6/2026
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
ModificadaAlta (7.8)0.48%—Nvidia Shield Experience9/10/201917/6/2026
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial…
ModificadaAlta (7.8)1.2%💥 ExploitExtenua Silvershield17/8/201917/6/2026
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.
ModificadaAlta (7.8)0.46%—Nvidia Shield Experience13/8/201917/6/2026
NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the custom NVIDIA API used in the mount system service where user data could be overridden, which may lead to code execution, denial of service, or information disclosure.
ModificadaAlta (7.8)0.41%—Nvidia Shield Experience6/8/201917/6/2026
NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the NVIDIA Games App where it improperly exports an Activity but does not properly restrict which applications can launch the Activity, which may lead to code execution or denial of service.
ModificadaAlta (7.8)0.40%—Nvidia Shield Experience6/8/201917/6/2026
NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code execution, denial of service, or escalation of…
ModificadaAlta (8.2)0.39%—Stormshield Network Security4/7/201917/6/2026
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.
ModificadaMedia (6.1)0.88%—Oneshield Policy8/5/201917/6/2026
Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated…
ModificadaAlta (8.8)1.5%—Oneshield Policy8/5/201917/6/2026
A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can poison log files by entering malicious payloads in either headers or form elements. These payloads are then executed via a client side debugging console. This is…
ModificadaAlta (7.5)1.1%—Datashieldcoin Project Datashieldcoin9/7/201817/6/2026
The mintToken function of a smart contract implementation for DataShieldCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Hashshield Project Hashshield9/7/201817/6/2026
The mintToken function of a smart contract implementation for HashShield, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (8.8)2.2%💥 ExploitEcessa Shieldlink Sl175ehq Firmware1/7/201817/6/2026
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.
ModificadaAlta (7)0.10%—Nvidia Shield TV FirmwareGoogle Android6/3/201817/6/2026
NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.
ModificadaAlta (8.4)0.14%—Nvidia Shield TV FirmwareGoogle Android6/3/201817/6/2026
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rated as high.
ModificadaMedia (5.5)0.07%—Nvidia Shield TV FirmwareGoogle Android6/3/201817/6/2026
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as…
ModificadaMedia (5.5)0.15%—Nvidia Shield TV FirmwareGoogle Android6/3/201817/6/2026
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.
ModificadaAlta (7.8)0.15%—Nvidia Shield TV FirmwareGoogle Android6/3/201817/6/2026
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.
ModificadaCrítica (9.8)18%💥 ExploitIolo System Shield31/1/201817/6/2026
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.
ModificadaAlta (7.5)11%💥 ExploitAnchorfree Hotspot Shield31/1/201817/6/2026
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter…
ModificadaAlta (7.5)2.7%—Unshield Project Unshield28/8/201717/6/2026
Directory traversal vulnerability in unshield 1.0-1.
ModificadaMedia (6.8)0.35%—Thalesesecurity Nshield Connect Firmware18/8/201717/6/2026
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and…
ModificadaAlta (7.8)0.45%—Nvidia Shield Tablet FirmwareNvidia Shield Tablet TK1 FirmwareNvidia Shield TV FirmwareNvidia Video Driver24/4/201717/6/2026
Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
ModificadaAlta (7.8)0.45%—Nvidia Shield Tablet FirmwareNvidia Shield Tablet TK1 FirmwareNvidia Shield TV FirmwareNvidia Video Driver24/4/201717/6/2026
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
Orbitaley — Vulnerabilidades