Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.9) | 0.13% | — | ShimAIDp.cAI | 10/8/2026 | 14/8/2026 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader. | |
| Aplazada | Alta (7.8) | 0.11% | — | Microsoft Uefi Shim BootloaderAI | 9/6/2026 | 23/7/2026 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads.… | |
| Aplazada | Media (6.9) | 0.40% | — | SpinwasmAIContainerd-shim-spinAISpinroot SpinAI | 26/2/2026 | 17/6/2026 | Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to… | |
| Aplazada | Media (4.1) | 0.08% | — | Fedora ShimAI | 14/8/2025 | 17/6/2026 | The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded. | |
| Aplazada | Alta (7.1) | 0.23% | — | Fukushima KumihimoAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fukushima Kumihimo kumihimo allows Reflected XSS.This issue affects Kumihimo: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.32% | — | Takashimatsuyama Posts FilterAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Filter posts-filter allows Stored XSS.This issue affects Posts Filter: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Takashimatsuyama Browsing HistoryAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Browsing History browsing-history allows Stored XSS.This issue affects Browsing History: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.34% | — | Takashimatsuyama Posts SearchAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Search posts-search allows Stored XSS.This issue affects Posts Search: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Takashimatsuyama MY FavoritesAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows Stored XSS.This issue affects My Favorites: from n/a through <= 1.4.1. | |
| Modificada | Media (5.4) | 0.30% | — | Takashimatsuyama MY Favorites | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows DOM-Based XSS.This issue affects My Favorites: from n/a through <= 1.4.3. | |
| Modificada | Media (5.1) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.41% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.44% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain… | |
| Modificada | Alta (7.4) | 0.44% | — | Redhat ShimFedoraproject Fedora | 29/1/2024 | 26/6/2026 | A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory… | |
| Modificada | Alta (8.3) | 5.4% | — | Redhat ShimRedhat Enterprise Linux | 25/1/2024 | 26/6/2026 | A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This… | |
| Modificada | Alta (8.8) | 0.52% | — | Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+5 | 12/10/2023 | 17/6/2026 | Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the… | |
| Modificada | Media (6.5) | 0.46% | — | YKC Tokushima Awayokocho | 18/9/2023 | 9/7/2026 | An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Alta (7.8) | 0.33% | — | Redhat Shim | 20/7/2023 | 17/6/2026 | There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not… | |
| Modificada | Crítica (9.8) | 1.1% | — | Mailbutler Shimo | 4/5/2023 | 17/6/2026 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use. | |
| Modificada | Crítica (9.8) | 1.2% | — | Browserify-shim Project Browserify-shim | 31/10/2022 | 17/6/2026 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. | |
| Modificada | Crítica (9.8) | 1.1% | — | Browserify-shim Project Browserify-shim | 28/10/2022 | 17/6/2026 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. | |
| Modificada | Crítica (9.8) | 1.3% | — | Browserify-shim Project Browserify-shim | 11/10/2022 | 17/6/2026 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js. | |
| Modificada | Media (5.5) | 0.37% | — | Rashim Michlol | 5/8/2022 | 17/6/2026 | Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the… | |
| Modificada | Crítica (10) | 1.8% | — | Agoric Realms-shim | 10/1/2022 | 17/6/2026 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |