Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.63%—Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+113/4/202417/6/2026
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment…
AnalizadaMedia (6.5)0.40%—Dell Storage Monitoring AND ReportingDell Storage Resource Manager12/4/202417/6/2026
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.
AnalizadaMedia (6.8)0.27%—IBM Storage Defender Resiliency Service12/4/202417/6/2026
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.
AnalizadaAlta (7.8)0.15%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+893/4/202417/6/2026
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
AplazadaMedia (6.5)0.35%—Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+127/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and…
AplazadaCrítica (9.9)0.51%—Hitachi Virtual Storage PlatformAIHitachi Virtual Storage Platform Vp9500AIHitachi Virtual Storage Platform G1000AIHitachi Virtual Storage Platform G1500AI+3725/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, Hitachi Virtual Storage Platform…
AnalizadaMedia (5.5)0.12%—IBM Storage Protect Plus21/3/202417/6/2026
The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205.
ModificadaMedia (4.3)0.33%—IBM Storage Protect Plus21/3/202417/6/2026
IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.
AnalizadaAlta (8.4)0.20%—Dell Poweredge T360 FirmwareDell Poweredge R360 FirmwareDell Poweredge R650 FirmwareDell Poweredge R750 Firmware+8213/3/202417/6/2026
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
AnalizadaMedia (6.5)0.46%—Dell Elastic Cloud Storage28/2/202417/6/2026
Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace
ModificadaMedia (5.3)0.39%—Zestard Admin Side Data Storage FOR Contact Form 723/2/202417/6/2026
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter the message read…
ModificadaMedia (5.3)0.37%—Zestard Admin Side Data Storage FOR Contact Form 723/2/202417/6/2026
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark…
ModificadaMedia (4.3)0.20%—Zestard Admin Side Data Storage FOR Contact Form 723/2/202417/6/2026
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the settings update function. This makes it possible for unauthenticated attackers to update the plugin's…
ModificadaAlta (7.2)0.56%—Zestard Admin Side Data Storage FOR Contact Form 723/2/202417/6/2026
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaAlta (7.5)0.40%—IBM Spectrum Scale Container Native Storage Access17/2/202417/6/2026
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
AnalizadaMedia (6.5)0.14%—IBM Spectrum Scale Container Native Storage Access17/2/202417/6/2026
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
ModificadaMedia (4.3)0.38%—Oracle ZFS Storage Appliance KIT17/2/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of…
AnalizadaMedia (6.9)0.31%—Netapp Storagegrid16/2/202417/6/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted…
AnalizadaMedia (6.5)0.49%—Netapp Storagegrid16/2/202417/6/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition or node reboot.
AnalizadaCrítica (9.8)0.59%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
AnalizadaCrítica (9.8)0.64%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
ModificadaMedia (6.4)0.13%—Intel Memory AND Storage Tool14/2/202417/6/2026
Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.20%—Intel Memory AND Storage Tool14/2/202417/6/2026
Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.13%—IBM Storage Defender Resiliency Service10/2/202417/6/2026
IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749.
ModificadaMedia (5.5)0.15%—IBM Storage Defender Resiliency Service10/2/202417/6/2026
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.