Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

703 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.67%—Dell Powerscale Onefs25/3/202417/6/2026
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaBaja (2.3)0.14%—Dell Powerscale Onefs4/3/202417/6/2026
Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
AnalizadaCrítica (9.1)0.28%—Dell Powerscale Onefs4/3/202417/6/2026
Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information
AnalizadaMedia (4.3)0.49%—Redhat 3scale28/2/202417/6/2026
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a…
AnalizadaAlta (7.5)0.40%—IBM Spectrum Scale Container Native Storage Access17/2/202417/6/2026
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
AnalizadaMedia (6.5)0.14%—IBM Spectrum Scale Container Native Storage Access17/2/202417/6/2026
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
ModificadaBaja (3.3)0.10%—AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+4313/2/202417/6/2026
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.
ModificadaAlta (7.8)0.17%—Dell Powerscale Onefs1/2/202417/6/2026
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.
ModificadaMedia (5.5)0.14%—Dell Powerscale Onefs1/2/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.
ModificadaAlta (7.5)0.34%—Zscaler Secure Internet AND Saas Access31/1/202417/6/2026
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
AnalizadaAlta (7.5)58%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
AnalizadaAlta (8.8)3.2%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
ModificadaMedia (6.8)0.19%—Scalefusion11/1/202417/6/2026
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
ModificadaMedia (4.6)0.29%—Scalefusion11/1/202417/6/2026
ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."
ModificadaAlta (8.8)0.31%—Scalefusion11/1/202417/6/2026
ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."
ModificadaAlta (8.8)0.31%—Scalefusion11/1/202417/6/2026
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
ModificadaAlta (8.8)0.29%—Scalefusion11/1/202417/6/2026
In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
ModificadaAlta (7.5)0.41%—IBM Spectrum Scale14/12/202317/6/2026
IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080.
ModificadaAlta (8.1)0.35%—Dell Powerscale Onefs5/12/202317/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
ModificadaAlta (7.5)0.70%—Dell Powerscale Onefs5/12/202317/6/2026
Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.
ModificadaCrítica (9.1)35%💥 ExploitAnyscale RAY28/11/202317/6/2026
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
ModificadaCrítica (9.8)84%💥 ExploitAnyscale RAY28/11/202317/6/2026
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that…
ModificadaMedia (5.4)0.23%—Zscaler Client Connector21/11/202317/6/2026
An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149.
ModificadaAlta (7.5)0.66%—Juanfont Headscale11/11/202317/6/2026
Headscale through 0.22.3 writes bearer tokens to info-level logs.
ModificadaMedia (5.5)0.22%—Redhat 3scale API Management6/11/202317/6/2026
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
Orbitaley — Vulnerabilidades