Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.16%—Dell Command Powershell ProviderAI21/9/202624/9/2026
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Pendiente de análisisMedia (6.5)0.37%—Devolutions Powershell UniversalAI15/9/202616/9/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
En análisisAlta (8.8)0.30%—Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex…
AnalizadaAlta (7.8)0.32%—Microsoft Powershell14/8/202618/8/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Pendiente de análisisAlta (8.1)0.39%—Devolutions Powershell UniversalAI14/8/202628/8/2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the…
AnalizadaAlta (7.8)0.36%—Microsoft Powershell11/8/202614/8/2026
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.94%—Microsoft Powershell11/8/202614/8/2026
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.3)0.38%—Microsoft Powershell11/8/202617/8/2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.87%—Microsoft Powershell11/8/202617/8/2026
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.10%—Devolutions Powershell Universal24/7/202629/7/2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the…
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
AnalizadaMedia (5)0.25%—Devolutions Powershell Universal24/7/202629/7/2026
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.
AnalizadaMedia (6.5)0.38%—Devolutions Powershell Universal24/7/202629/7/2026
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
AnalizadaMedia (6.5)0.44%—Devolutions Powershell Universal29/6/20262/7/2026
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
AnalizadaMedia (5.3)0.37%—Ironmansoftware Powershell Universal12/6/202617/6/2026
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
ModificadaAlta (7.5)2.3%—Microsoft .netMicrosoft Powershell14/4/202615/7/2026
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)0.47%—Microsoft Powershell14/4/202617/6/2026
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.3)0.38%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service…
AnalizadaMedia (5.5)0.40%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a…
ModificadaMedia (6.5)0.22%—Ironmansoftware Powershell Universal27/2/202617/6/2026
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials
AnalizadaMedia (6.8)0.10%—Icinga Powershell Framework29/1/202617/6/2026
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of…
AnalizadaMedia (6.1)0.18%—Ironmansoftware Powershell Universal7/1/202617/6/2026
Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.
AnalizadaAlta (7.3)0.48%—Microsoft PowershellMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1314/10/202517/6/2026
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.33%—Microsoft PowershellMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+99/9/202517/6/2026
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.