Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.42% | — | Nvidia Shield Tablet FirmwareNvidia Shield Tablet TK1 FirmwareNvidia Shield TV FirmwareNvidia Video Driver | 24/4/2017 | 17/6/2026 | Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5 allows local users to cause a denial of service (system crash) via unspecified vectors, which triggers a buffer overflow. | |
| Modificada | Alta (7.8) | 0.50% | — | Flexera Installshield | 24/2/2016 | 17/6/2026 | Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. | |
| Modificada | Media (5.4) | 0.27% | — | Steganos Online Shield VPN | 18/9/2014 | 17/6/2026 | The Steganos Online Shield VPN (aka com.steganos.onlineshield) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ocshield Datagard VPN + AV | 9/9/2014 | 17/6/2026 | The DataGard VPN + AV (aka ocshield.com) application @7F050013 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.2) | 0.29% | — | Pcsecurityshield Security Shield 2010 | 25/8/2012 | 16/6/2026 | Race condition in Security Shield 2010 13.0.16.313 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka… | |
| Modificada | Media (6.5) | 1.6% | — | Mcafee Linuxshield | 22/8/2012 | 16/6/2026 | McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin access to the statistics server by leveraging a client account. | |
| Modificada | Media (6.8) | 1.4% | — | Vmware Vshield Manager | 16/3/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Baja (2.1) | 0.30% | — | Flexerasoftware Installshield | 19/1/2012 | 16/6/2026 | Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between… | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Alta (7.2) | 0.75% | 💥 Exploit | Kingsoft Webshield | 24/5/2010 | 16/6/2026 | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Mcafee Intrushield Network Security Manager | 13/11/2009 | 16/6/2026 | McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Mcafee Intrushield Network Security Manager | 13/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter. | |
| Modificada | Alta (9.3) | 2.8% | — | Mcafee Groupshield | 5/5/2009 | 16/6/2026 | McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an… | |
| Modificada | Alta (7.6) | 2.8% | — | Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+9 | 30/4/2009 | 16/6/2026 | The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in… | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | K2sxs Silvershield | 19/2/2009 | 16/6/2026 | SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. | |
| Modificada | Alta (9.3) | 1.6% | — | Acresso Flexnet ConnectAcresso Intallshield Update Agent | 18/9/2008 | 16/6/2026 | Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules. | |
| Analizada | Alta (9.3) | 2.2% | — | Revenera Installshield | 4/4/2008 | 16/6/2026 | The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Macrovision Flexnet ConnectMacrovision Installshield 2008Macrovision Update Service | 2/11/2007 | 16/6/2026 | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow. | |
| Modificada | Media (5) | 2.0% | — | Cisco WebnsOpenbsd OpensshTeamf1 Sshield | 4/9/2007 | 16/6/2026 | Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack… | |
| Modificada | Media (4.6) | 0.33% | — | Credant Mobile Guardian Shield - Windows | 30/5/2007 | 16/6/2026 | Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the… | |
| Modificada | Alta (10) | 6.1% | — | Mcafee Webshield Smtp | 4/4/2006 | 16/6/2026 | Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed. | |
| Modificada | Baja (2.6) | 0.92% | — | Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+4 | 9/3/2006 | 16/6/2026 | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote… | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Baja (1.9) | 0.54% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp. | |
| Modificada | Alta (7.5) | 1.6% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack. |