Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.41% | — | Gnome-shell | 29/4/2014 | 17/6/2026 | js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search. | |
| Modificada | Media (6.8) | 1.3% | — | Gnome-shell | 1/10/2012 | 16/6/2026 | The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page. | |
| Modificada | Media (5) | 1.2% | — | Phpdevshell | 24/9/2011 | 16/6/2026 | PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by gzip.php. | |
| Modificada | Media (6.9) | 0.31% | — | Gnome-shell | 6/11/2010 | 16/6/2026 | gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (4.3) | 1.0% | — | Myshell Evalsmsi | 11/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Myshell Evalsmsi | 11/2/2010 | 16/6/2026 | evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability. | |
| Modificada | Media (4.3) | 1.3% | — | Myshell Evalsmsi | 11/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Myshell Evalsmsi | 11/2/2010 | 16/6/2026 | SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions. | |
| Modificada | Alta (9.3) | 5.4% | — | Ftpshell | 24/9/2009 | 16/6/2026 | Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command. | |
| Modificada | Alta (10) | 2.1% | — | Mark Reinsfelder Metashell | 10/9/2009 | 16/6/2026 | Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability. | |
| Modificada | Alta (10) | 90% | — | Zeroshell | 12/2/2009 | 16/6/2026 | cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action. | |
| Modificada | Alta (9.3) | 5.9% | — | Ftpshell Server | 29/1/2009 | 16/6/2026 | Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file. | |
| Modificada | Alta (10) | 1.2% | — | Phpdevshell | 30/11/2007 | 16/6/2026 | Unspecified vulnerability in PHPDevShell before 0.7.0 has unknown impact and attack vectors, involving a "minor security bug in repair & optimize database." | |
| Modificada | Alta (8.5) | 1.5% | — | Phpdevshell | 30/11/2007 | 16/6/2026 | PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.8) | 1.6% | — | VAN Dyke Technologies Vshell | 20/11/2007 | 16/6/2026 | Unspecified vulnerability in VanDyke VShell 3.0.1 allows remote attackers to cause a denial of service via unspecified vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been… | |
| Modificada | Alta (10) | 4.6% | — | SKY Software Shcombobox Activex ControlSKY Software Shell Megapack Activex | 24/5/2007 | 16/6/2026 | Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.8) | 38% | — | Incredimail Immenushellext Activex Control | 26/4/2007 | 16/6/2026 | Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.0% | — | Wineggdropshell | 4/12/2005 | 16/6/2026 | Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server. | |
| Modificada | Baja (2.1) | 1.4% | — | Ftpshell Server | 3/8/2005 | 16/6/2026 | FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command. | |
| Modificada | Alta (10) | 2.6% | — | Iron Bars Shell | 24/5/2005 | 16/6/2026 | Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call. | |
| Modificada | Media (5) | 2.0% | — | SSH Secure Shell | 31/12/2003 | 16/6/2026 | SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets. | |
| Modificada | Alta (7.5) | 3.6% | — | SSH Secure Shell FOR Servers | 31/12/2002 | 16/6/2026 | SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server. | |
| Modificada | Alta (10) | 6.1% | — | Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+3 | 23/12/2002 | 16/6/2026 | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as… | |
| Modificada | Alta (10) | 5.8% | — | Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+3 | 23/12/2002 | 16/6/2026 | Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. | |
| Modificada | Alta (10) | 9.8% | — | Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+3 | 23/12/2002 | 16/6/2026 | Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. |