Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.38%—Shell-quoteAI29/9/202630/9/2026
shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is…
Pendiente de análisisAlta (7.8)0.16%—Dell Command Powershell ProviderAI21/9/202624/9/2026
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Pendiente de análisisMedia (6.5)0.37%—Devolutions Powershell UniversalAI15/9/202616/9/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
Pendiente de análisisMedia (6.1)0.13%—Gnome ShellAI15/9/202616/9/2026
A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an…
En análisisAlta (8.8)0.30%—Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex…
AnalizadaCrítica (9.9)0.80%—Nvidia Openshell25/8/20261/9/2026
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (8.5)0.63%—Nvidia Openshell25/8/20261/9/2026
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
AnalizadaAlta (8.8)2.6%—Nvidia Openshell25/8/20262/9/2026
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaMedia (6.8)2.4%—Nvidia Openshell25/8/20263/9/2026
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
AnalizadaMedia (5.2)0.17%—Nvidia Openshell25/8/20263/9/2026
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
AnalizadaCrítica (9.9)0.86%—Nvidia Openshell25/8/20263/9/2026
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
AplazadaAlta (8.4)0.27%—Git-scm GITAISonirico Mcp-shellAI25/8/20269/9/2026
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the…
AplazadaAlta (8.4)0.45%—Sonirico Mcp-shellAI25/8/20269/9/2026
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A…
AplazadaAlta (8.6)0.20%—Sonirico Mcp-shellAI25/8/20269/9/2026
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in…
AnalizadaAlta (7.8)0.32%—Microsoft Powershell14/8/202618/8/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Pendiente de análisisAlta (8.1)0.39%—Devolutions Powershell UniversalAI14/8/202628/8/2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the…
AnalizadaAlta (7.8)0.36%—Microsoft Powershell11/8/202614/8/2026
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.94%—Microsoft Powershell11/8/202614/8/2026
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.3)0.38%—Microsoft Powershell11/8/202617/8/2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.87%—Microsoft Powershell11/8/202617/8/2026
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (5.9)0.37%—Penelope Shell HandlerAI29/7/202610/9/2026
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised…
AnalizadaMedia (6.5)0.10%—Devolutions Powershell Universal24/7/202629/7/2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the…
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
AnalizadaMedia (5)0.25%—Devolutions Powershell Universal24/7/202629/7/2026
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.