Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.38% | — | Shell-quoteAI | 29/9/2026 | 30/9/2026 | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Dell Command Powershell ProviderAI | 21/9/2026 | 24/9/2026 | Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Devolutions Powershell UniversalAI | 15/9/2026 | 16/9/2026 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to… | |
| Pendiente de análisis | Media (6.1) | 0.13% | — | Gnome ShellAI | 15/9/2026 | 16/9/2026 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an… | |
| En análisis | Alta (8.8) | 0.30% | — | Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex… | |
| Analizada | Crítica (9.9) | 0.80% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (8.5) | 0.63% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Alta (8.8) | 2.6% | — | Nvidia Openshell | 25/8/2026 | 2/9/2026 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Media (6.8) | 2.4% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Analizada | Media (5.2) | 0.17% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Crítica (9.9) | 0.86% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. | |
| Aplazada | Alta (8.4) | 0.27% | — | Git-scm GITAISonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the… | |
| Aplazada | Alta (8.4) | 0.45% | — | Sonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A… | |
| Aplazada | Alta (8.6) | 0.20% | — | Sonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in… | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Powershell | 14/8/2026 | 18/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Devolutions Powershell UniversalAI | 14/8/2026 | 28/8/2026 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Powershell | 11/8/2026 | 14/8/2026 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Powershell | 11/8/2026 | 14/8/2026 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.3) | 0.38% | — | Microsoft Powershell | 11/8/2026 | 17/8/2026 | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.87% | — | Microsoft Powershell | 11/8/2026 | 17/8/2026 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (5.9) | 0.37% | — | Penelope Shell HandlerAI | 29/7/2026 | 10/9/2026 | Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised… | |
| Analizada | Media (6.5) | 0.10% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected. | |
| Analizada | Alta (8.8) | 0.53% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the… | |
| Analizada | Alta (8.8) | 0.53% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation. | |
| Analizada | Media (5) | 0.25% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks. |