Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (3.9)0.13%—ShimAIDp.cAI10/8/202614/8/2026
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.
AplazadaAlta (7.8)0.11%—Microsoft Uefi Shim BootloaderAI9/6/202623/7/2026
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads.…
AplazadaMedia (6.9)0.40%—SpinwasmAIContainerd-shim-spinAISpinroot SpinAI26/2/202617/6/2026
Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to…
AplazadaMedia (4.1)0.08%—Fedora ShimAI14/8/202517/6/2026
The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.
AplazadaAlta (7.1)0.23%—Fukushima KumihimoAI23/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fukushima Kumihimo kumihimo allows Reflected XSS.This issue affects Kumihimo: from n/a through <= 1.0.2.
AplazadaMedia (6.5)0.32%—Takashimatsuyama Posts FilterAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Filter posts-filter allows Stored XSS.This issue affects Posts Filter: from n/a through <= 1.3.1.
AplazadaMedia (6.5)0.33%—Takashimatsuyama Browsing HistoryAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Browsing History browsing-history allows Stored XSS.This issue affects Browsing History: from n/a through <= 1.3.1.
AplazadaMedia (6.5)0.34%—Takashimatsuyama Posts SearchAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Search posts-search allows Stored XSS.This issue affects Posts Search: from n/a through <= 1.2.2.
AplazadaMedia (6.5)0.27%—Takashimatsuyama MY FavoritesAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows Stored XSS.This issue affects My Favorites: from n/a through <= 1.4.1.
ModificadaMedia (5.4)0.30%—Takashimatsuyama MY Favorites22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows DOM-Based XSS.This issue affects My Favorites: from n/a through <= 1.4.3.
ModificadaMedia (5.1)0.40%—Redhat ShimFedoraproject FedoraRedhat Enterprise Linux29/1/202417/6/2026
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
ModificadaMedia (5.5)0.40%—Redhat ShimFedoraproject FedoraRedhat Enterprise Linux29/1/202417/6/2026
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.
ModificadaMedia (5.5)0.41%—Redhat ShimFedoraproject FedoraRedhat Enterprise Linux29/1/202417/6/2026
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
ModificadaMedia (5.5)0.44%—Redhat ShimFedoraproject FedoraRedhat Enterprise Linux29/1/202417/6/2026
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain…
ModificadaAlta (7.4)0.44%—Redhat ShimFedoraproject Fedora29/1/202426/6/2026
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory…
ModificadaAlta (8.3)5.4%—Redhat ShimRedhat Enterprise Linux25/1/202426/6/2026
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This…
ModificadaAlta (8.8)0.52%—Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+512/10/202317/6/2026
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the…
ModificadaMedia (6.5)0.46%—YKC Tokushima Awayokocho18/9/20239/7/2026
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaAlta (7.8)0.33%—Redhat Shim20/7/202317/6/2026
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not…
ModificadaCrítica (9.8)1.1%—Mailbutler Shimo4/5/202317/6/2026
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
ModificadaCrítica (9.8)1.2%—Browserify-shim Project Browserify-shim31/10/202217/6/2026
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.
ModificadaCrítica (9.8)1.1%—Browserify-shim Project Browserify-shim28/10/202217/6/2026
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.
ModificadaCrítica (9.8)1.3%—Browserify-shim Project Browserify-shim11/10/202217/6/2026
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
ModificadaMedia (5.5)0.37%—Rashim Michlol5/8/202217/6/2026
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the…
ModificadaCrítica (10)1.8%—Agoric Realms-shim10/1/202217/6/2026
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.