Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.26% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.49% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths. | |
| Analizada | Alta (8.8) | 0.53% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. | |
| Analizada | Crítica (9.8) | 0.63% | — | Dell Powerstoreos | 31/8/2026 | 1/10/2026 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability… | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 1/9/2026 | Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (8.8) | 0.46% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 1/9/2026 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.5) | 0.22% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Media (6.5) | 0.31% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (8.8) | 2.0% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (4.3) | 0.27% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.5) | 0.48% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Alta (8.8) | 1.7% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (6.5) | 0.30% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 2/9/2026 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Media (5.9) | 0.29% | — | Dell Idrac9AI | 26/8/2026 | 28/8/2026 | Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data. | |
| Analizada | Alta (7.2) | 1.6% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Crítica (9.1) | 2.0% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Pendiente de análisis | Media (6.6) | 0.14% | — | Dell Client BiosAI | 24/8/2026 | 28/8/2026 | Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Thinos | 24/8/2026 | 2/9/2026 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |