Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.67% | — | Dell Powerscale Onefs | 25/3/2024 | 17/6/2026 | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Baja (2.3) | 0.14% | — | Dell Powerscale Onefs | 4/3/2024 | 17/6/2026 | Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period. | |
| Analizada | Crítica (9.1) | 0.28% | — | Dell Powerscale Onefs | 4/3/2024 | 17/6/2026 | Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information | |
| Analizada | Media (4.3) | 0.49% | — | Redhat 3scale | 28/2/2024 | 17/6/2026 | A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a… | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Spectrum Scale Container Native Storage Access | 17/2/2024 | 17/6/2026 | IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. | |
| Analizada | Media (6.5) | 0.14% | — | IBM Spectrum Scale Container Native Storage Access | 17/2/2024 | 17/6/2026 | IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811. | |
| Modificada | Baja (3.3) | 0.10% | — | AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+43 | 13/2/2024 | 17/6/2026 | Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Powerscale Onefs | 1/2/2024 | 17/6/2026 | Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access. | |
| Modificada | Media (5.5) | 0.14% | — | Dell Powerscale Onefs | 1/2/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Alta (7.5) | 0.34% | — | Zscaler Secure Internet AND Saas Access | 31/1/2024 | 17/6/2026 | In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic. | |
| Analizada | Alta (7.5) | 58% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | |
| Analizada | Alta (8.8) | 3.2% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. | |
| Modificada | Media (6.8) | 0.19% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | |
| Modificada | Media (4.6) | 0.29% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules." | |
| Modificada | Alta (8.8) | 0.31% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules." | |
| Modificada | Alta (8.8) | 0.31% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | |
| Modificada | Alta (8.8) | 0.29% | — | Scalefusion | 11/1/2024 | 17/6/2026 | In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | |
| Modificada | Alta (7.5) | 0.41% | — | IBM Spectrum Scale | 14/12/2023 | 17/6/2026 | IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080. | |
| Modificada | Alta (8.1) | 0.35% | — | Dell Powerscale Onefs | 5/12/2023 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | |
| Modificada | Alta (7.5) | 0.70% | — | Dell Powerscale Onefs | 5/12/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.1) | 35% | 💥 Exploit | Anyscale RAY | 28/11/2023 | 17/6/2026 | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Anyscale RAY | 28/11/2023 | 17/6/2026 | Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that… | |
| Modificada | Media (5.4) | 0.23% | — | Zscaler Client Connector | 21/11/2023 | 17/6/2026 | An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149. | |
| Modificada | Alta (7.5) | 0.66% | — | Juanfont Headscale | 11/11/2023 | 17/6/2026 | Headscale through 0.22.3 writes bearer tokens to info-level logs. | |
| Modificada | Media (5.5) | 0.22% | — | Redhat 3scale API Management | 6/11/2023 | 17/6/2026 | A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. |