Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)1.1%—GMS Command-line InterfaceAI11/8/202628/8/2026
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
AnalizadaMedia (6.6)0.24%—Oracle Cloud Native Environment Command Line Interface6/5/202617/6/2026
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a…
AnalizadaMedia (5.6)0.14%—Home-assistant-ecosystem Home Assistant Command-line Interface21/4/202617/6/2026
The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This…
AnalizadaAlta (7.5)0.49%—Github Copilot Command Line Interface6/3/202617/6/2026
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server responses, or user…
ModificadaAlta (7)0.47%—Docker Command Line Interface4/3/202615/7/2026
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens…
AplazadaMedia (6.9)0.65%—Amazon Serverless Application Model Command Line InterfaceAI31/3/202517/6/2026
After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outside of the Docker…
AnalizadaAlta (8.4)0.42%—Microsoft Azure Command-line Interface11/3/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.
AnalizadaCrítica (9.1)1.6%—Microsoft Azure Command-line InterfaceMicrosoft Azure Service Connector8/10/202417/6/2026
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
AnalizadaMedia (4.3)0.13%—Google Firebase Command Line Interface2/5/202417/6/2026
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie…
ModificadaMedia (5.5)0.29%—Appwrite Command Line Interface9/1/202417/6/2026
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
AnalizadaAlta (8.6)21%—Microsoft Azure Command-line Interface14/11/202317/6/2026
Azure CLI REST Command Information Disclosure Vulnerability
ModificadaAlta (7.8)0.17%—NI Labview Command Line Interface1/12/202217/6/2026
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)3.5%—Microsoft Azure Command-line Interface25/10/202217/6/2026
Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is…
ModificadaAlta (7.8)0.19%—Dell Powerstore Command Line Interface21/7/202217/6/2026
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.
ModificadaMedia (4.8)0.52%—1password1password IN THE Browser1password Command-line1password Command Line Interface+215/6/202217/6/2026
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.
ModificadaAlta (7.5)1.7%—Docker Command Line InterfaceFedoraproject Fedora4/10/202117/6/2026
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would…
ModificadaCrítica (9.8)0.87%—1password Command Line Interface1password Scim27/10/202017/6/2026
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force…
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (8.8)1.3%—Cloudfoundry Command Line Interface7/3/201917/6/2026
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.
ModificadaMedia (6.5)1.1%—Clusterlabs Pacemaker Command Line InterfaceRedhat Enterprise Linux12/4/201817/6/2026
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could…
ModificadaAlta (7.5)1.9%—Clusterlabs Pacemaker Command Line InterfaceDebian LinuxRedhat Enterprise Linux Server EUS12/4/201817/6/2026
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their…