Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | — | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Alta (8.2) | — | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Crítica (9.6) | — | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is… | |
| Pendiente de análisis | Alta (7.4) | — | — | Dell Command ConfigureAI | 6/10/2026 | 6/10/2026 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Pendiente de análisis | Alta (7.3) | — | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution. | |
| Pendiente de análisis | Media (5.5) | — | — | Dell Command ConfigureAI | 6/10/2026 | 6/10/2026 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Pendiente de análisis | Alta (7.6) | — | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Pendiente de análisis | Media (6.2) | — | — | Dell Command ConfigureAI | 6/10/2026 | 6/10/2026 | Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Alta (8.8) | — | — | Dell Openmanage IntegrationAI | 6/10/2026 | 7/10/2026 | Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote… | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Alta (7.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation… | |
| Pendiente de análisis | Crítica (9.6) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Alta (8.2) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | |
| Pendiente de análisis | Media (6.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Media (5.4) | — | — | Dell Csi-powerflexAIDell Csi-powermaxAIDell Csi-powerstoreAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Media (6.5) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Crítica (9.9) | — | — | Dell Container Storage Modules OperatorAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining… | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend… | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8 | |
| Analizada | Media (5.9) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.4) | 0.15% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |