Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.53% | — | Shadowclonelabs Glutamate MCP Servers | 27/4/2026 | 17/6/2026 | A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request… | |
| Aplazada | Alta (8.5) | 0.19% | — | Minitool ShadowmakerAI | 26/1/2026 | 17/6/2026 | MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges. | |
| Aplazada | Alta (7.7) | 0.47% | — | Robmarsh Image ShadowAI | 27/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow image-shadow allows Path Traversal.This issue affects Image Shadow: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.6) | 0.40% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl,… | |
| Aplazada | Media (5.1) | 0.22% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000… | |
| Aplazada | Media (6.9) | 0.36% | — | Gl-inet GL A1300 Slate PlusAIGl-inet GL Ar300m16 ShadowAIGl-inet GL Ar300m ShadowAIGl-inet GL Ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000… | |
| Aplazada | Baja (3.6) | 0.42% | — | Shadow-utils ShadowAI | 26/12/2024 | 17/6/2026 | shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap… | |
| Aplazada | Media (6.3) | 0.61% | — | Drop Shadow BoxesAI | 16/11/2024 | 17/6/2026 | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.21% | — | W-shadow Admin Menu Editor | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: from n/a through 1.12. | |
| Modificada | Media (5.5) | 0.26% | — | Shadow-maint Shadow-utilsRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 27/12/2023 | 17/6/2026 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory. | |
| Modificada | Media (5.4) | 0.54% | — | Stevenhenty Drop Shadow Boxes | 22/11/2023 | 17/6/2026 | The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Shadowmaker | 19/9/2023 | 17/6/2026 | MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | |
| Modificada | Media (5.4) | 0.39% | — | Drop Shadow Boxes Project Drop Shadow Boxes | 25/7/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions. | |
| Modificada | Baja (3.3) | 0.43% | — | Shadow Project Shadow | 14/4/2023 | 17/6/2026 | In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r… | |
| Modificada | Crítica (9.8) | 0.39% | — | Shadowsocksx-ng | 3/3/2023 | 17/6/2026 | ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS. | |
| Modificada | Media (5.5) | 0.20% | — | Doomsider Shadow Project Doomsider Shadow | 19/2/2023 | 17/6/2026 | A vulnerability was found in doomsider shadow. It has been classified as problematic. Affected is an unknown function. The manipulation leads to denial of service. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be difficult. Continious delivery with… | |
| Modificada | Alta (7.8) | 0.40% | — | Debian ShadowDebian Linux | 17/3/2021 | 17/6/2026 | The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-physical means such as SSH (hence bypassing PAM's nullok_secure configuration). This notably affects… | |
| Modificada | Alta (7.8) | 0.52% | — | Shadow Project Shadow | 18/12/2019 | 17/6/2026 | shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and… | |
| Modificada | Alta (7.4) | 1.4% | — | Shadowsocks-libev | 18/12/2019 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send… | |
| Modificada | Alta (7.8) | 0.73% | — | Shadowsocks-libevOpensuse Backports SLEOpensuse Leap | 3/12/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.3% | — | Shadowsocks-libevOpensuse BackportsOpensuse Leap | 3/12/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability. | |
| Modificada | Media (4.7) | 0.30% | — | Debian ShadowDebian LinuxFedoraproject FedoraRedhat Enterprise Linux | 3/12/2019 | 16/6/2026 | shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees | |
| Modificada | Alta (8.1) | 1.7% | — | Blade-group Shadow | 14/11/2019 | 17/6/2026 | The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream. | |
| Modificada | Alta (7.8) | 0.63% | — | Debian ShadowSudo Project SudoDebian LinuxRedhat Enterprise Linux | 4/11/2019 | 16/6/2026 | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process. | |
| Modificada | Alta (7.8) | 0.30% | — | Suse Shadow | 26/9/2018 | 17/6/2026 | Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15 (SLE-15). Non-existing intermediate directories are created with mode 0777 during user creation.… |