Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.47%—Apache Shiro31/8/20261/9/2026
When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments…
AplazadaMedia (5.5)0.50%—Hcr707305003 ShiroiadminAI12/7/202613/7/2026
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly…
AplazadaBaja (2)0.30%—Apache ShiroAI25/6/202625/6/2026
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe…
AplazadaAlta (8.2)0.67%—Apache ShiroAIApache Shiro-guiceAI25/6/202625/6/2026
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. This vulnerability is similar to https://www.cve.org/CVERecord?id=CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice` module instead of…
AplazadaMedia (6.9)0.62%—Centraldogma-server-auth-shiroAI22/6/202622/6/2026
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause…
AnalizadaAlta (8.8)0.76%—Apache Shiro17/6/202618/6/2026
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used…
AnalizadaNinguna (0)0.45%—Apache Shiro25/5/202624/7/2026
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects…
AnalizadaMedia (5.1)0.49%—Apache Shiro25/5/202624/7/2026
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module. Users are recommended to upgrade to…
AnalizadaMedia (5.9)0.33%—Apache Shiro25/5/202624/7/2026
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native…
AnalizadaMedia (5.9)0.53%—Apache Shiro25/5/202624/7/2026
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not…
AplazadaBaja (2.9)0.46%—Perfree Go-fastdfs-webAIApache ShiroAI11/3/202617/6/2026
A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . The attack can be…
AnalizadaBaja (1)0.22%—Apache Shiro10/2/202617/6/2026
Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force…
ModificadaMedia (5.3)0.36%—Apache Shiro9/2/202620/8/2026
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS…
AnalizadaMedia (5.5)4.4%—Xuanshao Spring-shiro-training9/8/202517/6/2026
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.5)0.38%—Zhaojun1998 Shiro-action5/5/202517/6/2026
Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.
ModificadaMedia (6.5)1.2%—Apache Shiro15/1/202417/6/2026
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
ModificadaAlta (7.5)0.65%—Mandelo SSM Shiro Blog10/1/202417/6/2026
A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles of the component Backend. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (6.1)1.5%—Apache Shiro14/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
ModificadaCrítica (9.8)2.1%—Apache Shiro24/7/202317/6/2026
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
ModificadaAlta (7.5)0.78%—Akindo-sushiro Hong Kong SushiroAkindo-sushiro Singapore SushiroAkindo-sushiro SushiroAkindo-sushiro Taiwan Sushiro+113/2/202317/6/2026
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan…
ModificadaAlta (7.5)1.6%—Apache ShiroVmware Spring Boot14/1/202317/6/2026
When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching.…
ModificadaCrítica (9.8)2.7%—Apache Shiro12/10/202217/6/2026
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
ModificadaCrítica (9.8)26%—Apache Shiro29/6/202217/6/2026
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
ModificadaCrítica (9.8)77%—Apache ShiroOracle Financial Services Crime AND Compliance Management Studio17/9/202117/6/2026
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
ModificadaMedia (6.1)0.76%—Shiro8 List (order Management) Item Change17/9/202117/6/2026
Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.