Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Mailbutler Shimo | 4/5/2023 | 17/6/2026 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use. | |
| Modificada | Media (5.4) | 0.53% | — | Shimo Document | 22/11/2021 | 17/6/2026 | Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field. | |
| Modificada | Alta (7.1) | 0.39% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug. | |
| Modificada | Alta (7.8) | 0.68% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere on the system. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access… | |
| Modificada | Alta (7.8) | 0.68% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit. | |
| Modificada | Media (5.5) | 0.38% | — | Shimovpn Shimo VPN | 17/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privileged process on the system. An attacker would need local access to the machine for a successful exploit. | |
| Modificada | Alta (7.8) | 0.44% | — | Shimovpn Shimo VPN | 15/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug. | |
| Modificada | Alta (7.8) | 0.42% | — | Shimovpn Shimo VPN | 15/4/2019 | 17/6/2026 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their privileges to root. An attacker would… | |
| Modificada | Crítica (9.8) | 1.5% | — | Mailbutler Shimo | 7/2/2018 | 17/6/2026 | In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root. | |
| Modificada | Alta (7.5) | 1.5% | — | Mawashimono Nikki | 1/12/2011 | 16/6/2026 | Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Mawashimono Nikki | 30/11/2011 | 16/6/2026 | HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." |