Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.42% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783. | |
| Modificada | Alta (7.5) | 0.55% | — | IBM Storage Virtualize | 7/2/2024 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted system that would not be correctly validated by the Storwize server. This could lead to a user connecting to a malicious host, believing that it was a trusted system and… | |
| Modificada | Alta (7.5) | 0.70% | — | Netapp Storagegrid | 5/2/2024 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash of the Local Distribution Router (LDR) service. | |
| Modificada | Media (6.5) | 0.70% | — | IBM Storage Ceph | 2/2/2024 | 17/6/2026 | IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906. | |
| Modificada | Alta (7.1) | 0.14% | — | Hitachi Storage Plug-in | 30/1/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2. | |
| Modificada | Media (5.3) | 0.53% | — | Openlibraryfoundation Mod-remote-storage | 19/1/2024 | 14/7/2026 | Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types. | |
| Modificada | Media (5.4) | 0.33% | — | IBM Storage Defender Data Protect | 19/1/2024 | 17/6/2026 | IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… | |
| Modificada | Media (4.4) | 0.18% | — | Oracle ZFS Storage Appliance KIT | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Modificada | Alta (7.4) | 0.92% | — | Oracle OpenjdkOracle GraalvmOracle Graalvm FOR JDKOracle JDK+5 | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition:… | |
| Modificada | Alta (7.5) | 0.78% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+3 | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition: 21.3.8 and 22.3.4. Easily exploitable… | |
| Modificada | Media (5.9) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+4 | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and… | |
| Modificada | Baja (2.5) | 0.30% | — | Oracle GraalvmOracle JDKOracle JRENetapp Cloud Insights Acquisition Unit+2 | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u391; Oracle GraalVM Enterprise Edition: 20.3.12 and 21.3.8. Difficult to exploit vulnerability allows unauthenticated attacker with logon to… | |
| Modificada | Alta (7.4) | 0.92% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+4 | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition:… | |
| Modificada | Baja (2.3) | 0.19% | — | Oracle ZFS Storage Appliance KIT | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Modificada | Media (6.5) | 0.51% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link. | |
| Modificada | Alta (7.5) | 0.55% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server. | |
| Modificada | Media (5.4) | 0.35% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. | |
| Modificada | Media (6.1) | 0.41% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. | |
| Modificada | Alta (8.8) | 1.5% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands. | |
| Modificada | Alta (7.5) | 0.65% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server. | |
| Modificada | Media (6.1) | 0.38% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table. | |
| Modificada | Alta (8.8) | 0.32% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level. | |
| Modificada | Media (5.3) | 0.50% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command. | |
| Modificada | Alta (8) | 2.7% | — | Microsoft Azure Storage Mover | 9/1/2024 | 17/6/2026 | Azure Storage Mover Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 0.65% | — | Microchip Maxview Storage Manager | 9/1/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default… |