Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 32% | — | Vandyke Vshell | 2/5/2022 | 17/6/2026 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | |
| Modificada | Media (5) | 1.2% | — | Phpdevshell | 24/9/2011 | 16/6/2026 | PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by gzip.php. | |
| Modificada | Alta (8.5) | 1.5% | — | Phpdevshell | 30/11/2007 | 16/6/2026 | PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 1.2% | — | Phpdevshell | 30/11/2007 | 16/6/2026 | Unspecified vulnerability in PHPDevShell before 0.7.0 has unknown impact and attack vectors, involving a "minor security bug in repair & optimize database." | |
| Modificada | Alta (7.8) | 1.6% | — | VAN Dyke Technologies Vshell | 20/11/2007 | 16/6/2026 | Unspecified vulnerability in VanDyke VShell 3.0.1 allows remote attackers to cause a denial of service via unspecified vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been… | |
| Modificada | Alta (7.5) | 2.7% | — | VAN Dyke Technologies Vshell | 2/6/2001 | 16/6/2026 | Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers. | |
| Modificada | Baja (2.1) | 0.45% | — | VAN Dyke Technologies Vshell | 2/6/2001 | 16/6/2026 | VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users to conduct arbitrary port forwarding to other systems. |