Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.16% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation… | |
| Pendiente de análisis | Crítica (9.6) | 0.42% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Alta (8.2) | 0.12% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | |
| Pendiente de análisis | Media (6.1) | 0.23% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Crítica (9.9) | 0.53% | — | Dell Container Storage Modules OperatorAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining… | |
| En análisis | Crítica (10) | 0.65% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (10) | 0.79% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend… | |
| En análisis | Crítica (9.8) | 0.34% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (9.8) | 0.54% | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8 | |
| Aplazada | Media (5.9) | 0.19% | — | Supreme Modules LiteAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | |
| En análisis | Alta (8.5) | 0.23% | — | Regularlabs Modules AnywhereAI | 28/9/2026 | 30/9/2026 | Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who… | |
| Aplazada | Media (6.3) | 0.32% | — | Misp ModulesAI | 25/9/2026 | 25/9/2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event… | |
| Pendiente de análisis | Alta (7.3) | 0.22% | — | Environment-modulesAI | 15/9/2026 | 21/9/2026 | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is… | |
| Aplazada | Media (5.1) | 0.30% | — | Qlomodules QloappAI | 12/9/2026 | 23/9/2026 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's… | |
| Aplazada | Alta (8.1) | 0.19% | — | Regularlabs Modules AnywhereAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the… | |
| Aplazada | Media (5.3) | 0.28% | — | Kirby-modulesAI | 21/7/2026 | 23/7/2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in… | |
| Aplazada | Alta (8.3) | 0.40% | — | Misp-modulesAI | 13/7/2026 | 14/7/2026 | A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. However, IP addresses were compared against the blocked ranges without first… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Financials Common Modules | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Modificada | Alta (8.5) | 0.30% | — | Oracle Financials Common Modules | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Aplazada | Crítica (9.3) | 0.21% | — | Misp ModulesAI | 13/5/2026 | 17/6/2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home… | |
| Aplazada | Media (5.8) | 0.13% | — | Misp ModulesAI | 13/5/2026 | 17/6/2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side… |