Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.36% | — | ShescapeAI | 15/8/2026 | 31/8/2026 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command,… | |
| Aplazada | Crítica (9.2) | 0.89% | — | ShescapeAI | 12/8/2026 | 9/9/2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escapeAll APIs on Windows with shell set to cmd.exe, or with shell set to true when CMD is the default. An… | |
| Aplazada | Alta (8.7) | 0.59% | — | ShescapeAI | 12/8/2026 | 9/9/2026 | Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments when flagProtection is enabled, which is the default, making processing quadratic in input size across the escape,… | |
| Aplazada | Media (6.3) | 0.61% | — | ShescapeAI | 12/8/2026 | 9/9/2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem.… | |
| Aplazada | Media (6.3) | 0.59% | — | ShescapeAI | 12/8/2026 | 9/9/2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when Dash is the default, and interpolate the… | |
| Aplazada | Alta (8.4) | 0.18% | — | Hornerautomation CscapeAI | 25/6/2026 | 25/6/2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. | |
| Aplazada | Crítica (9.3) | 0.67% | — | TravelscapeAI | 8/6/2026 | 23/7/2026 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote… | |
| Aplazada | Alta (8.6) | 0.18% | — | Globalscape CuteftpAI | 25/5/2026 | 23/7/2026 | CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and… | |
| Pendiente de análisis | Baja (2) | 0.24% | — | SAP Landscape TransformationAI | 14/4/2026 | 17/6/2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a… | |
| Analizada | Media (6.3) | 0.22% | — | Inkscape | 27/3/2026 | 17/6/2026 | A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags. | |
| Aplazada | Alta (8.6) | 0.53% | — | Whitebox-studio ScapeAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16. | |
| Analizada | Media (6.9) | 0.30% | — | Shescape Project Shescape | 11/3/2026 | 17/6/2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications that interpolate the return value directly into a shell command string can cause an attacker-controlled value like secret[12] to expand… | |
| Aplazada | Media (4.3) | 0.13% | — | Copyscape PremiumAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through <= 1.4.1. | |
| Aplazada | Media (4.8) | 0.16% | — | InkscapeAI | 22/1/2026 | 17/6/2026 | MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously… | |
| Aplazada | Crítica (9.1) | 0.51% | — | SAP Landscape TransformationAI | 13/1/2026 | 17/6/2026 | SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Whitebox-studio ScapeAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= 1.5.13. | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Landscape TransformationAI | 12/8/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Alta (7.2) | 0.90% | — | Mitel Openscape Accounting ManagementAI | 23/6/2025 | 17/6/2026 | Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to upload arbitrary files and execute unauthorized commands. | |
| Aplazada | Alta (7.5) | 0.58% | — | Mitel Openscape XpressionsAI | 23/6/2025 | 17/6/2026 | A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive… | |
| Aplazada | Alta (7.7) | 0.35% | — | SAP Landscape TransformationAI | 13/5/2025 | 17/6/2026 | Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application. | |
| Aplazada | Alta (8.4) | 0.29% | — | Hornerautomation CscapeAI | 8/5/2025 | 17/6/2026 | Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape. | |
| Aplazada | Crítica (9.9) | 0.74% | — | SAP Landscape TransformationAI | 8/4/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Baja (2.1) | 0.19% | — | ShescapeAI | 25/3/2025 | 17/6/2026 | Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential environment variable exposure on Windows with CMD. This impact users of Shescape on Windows that explicitly configure `shell: 'cmd.exe'` or `shell: true` using any of… | |
| Aplazada | Alta (7.3) | 1.2% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could… | |
| Aplazada | Alta (8.8) | 0.59% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute… |