Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.22% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.6) | 4.1% | 💥 PoC | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Analizada | Alta (7.5) | 0.19% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects Client Connector on MacOS: before 3.4. | |
| Analizada | Media (5.5) | 0.11% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4. | |
| Analizada | Crítica (9.8) | 0.47% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7. | |
| Analizada | Alta (7.8) | 0.19% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7. | |
| Analizada | Alta (7.8) | 0.11% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows: before 4.1.0.62. | |
| Analizada | Crítica (9.8) | 0.43% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.30% | — | Zscaler Client Connector | 1/5/2024 | 17/6/2026 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2. | |
| Analizada | Alta (7.8) | 0.20% | — | Zscaler Client Connector | 1/5/2024 | 17/6/2026 | The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209 | |
| Analizada | Alta (8.1) | 0.37% | — | Zscaler Client Connector | 30/4/2024 | 17/6/2026 | Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1 | |
| Analizada | Alta (8.8) | 0.37% | — | IBM Storage Scale | 30/4/2024 | 17/6/2026 | IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208. | |
| Aplazada | Media (6.8) | 0.43% | — | HPE Compute Scale-up Server 3200AI | 17/4/2024 | 17/6/2026 | A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensitive information in log files. | |
| Analizada | Alta (7.2) | 1.1% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+64 | 15/4/2024 | 17/6/2026 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. | |
| Analizada | Alta (7.5) | 0.32% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Alta (7.5) | 0.59% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (6) | 0.19% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. | |
| Analizada | Media (6) | 0.19% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. | |
| Analizada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Media (5.5) | 0.16% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges. | |
| Analizada | Alta (7.8) | 0.27% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later. | |
| Analizada | Alta (7.8) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.8) | 0.24% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.1) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later. |