Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Aplazada | Media (4.3) | 0.49% | — | Gnome GvfsAI | 26/2/2026 | 17/6/2026 | A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP… | |
| Aplazada | Media (4.3) | 0.30% | — | Gnome GvfsAI | 26/2/2026 | 17/6/2026 | A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe… | |
| Analizada | Media (5.4) | 0.37% | — | Rustfs | 25/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an attacker can steal… | |
| Analizada | Crítica (9.1) | 0.41% | 💥 PoC | Rustfs | 25/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enables unauthorized file… | |
| Aplazada | Alta (8.3) | 7.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 23/2/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. | |
| Aplazada | Media (4.3) | 0.19% | — | Sparklewpthemes Fitness FSEAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.3) | 0.19% | — | Sparklewpthemes Hello FSEAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6. | |
| Analizada | Alta (8.1) | 0.53% | — | Lakefs | 13/2/2026 | 17/6/2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.HasPrefix() to verify… | |
| Aplazada | Media (5.4) | 1.4% | — | Grub-btrfsAIArchlinux Arch LinuxAI | 12/2/2026 | 17/6/2026 | grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details… | |
| Analizada | Crítica (9.8) | 0.47% | — | Ourway Webfsd | 12/2/2026 | 17/6/2026 | webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable | |
| Aplazada | Crítica (9.8) | 0.55% | — | Metis DFSAI | 11/2/2026 | 17/6/2026 | METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compromise of the software, granting… | |
| Analizada | Media (6.9) | 0.55% | — | Friendsofshopware Froshadminer | 9/2/2026 | 17/6/2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. This vulnerability… | |
| Analizada | Media (6.9) | 0.28% | — | Rustfs | 3/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) to application logs at INFO level. This results in credentials being recorded in plaintext in log output, which may be accessible to… | |
| Analizada | Alta (7.7) | 0.24% | — | Rustfs | 3/2/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable client can spoof aws:SourceIp and satisfy IP-allowlist policies.… | |
| Analizada | Media (4.8) | 0.17% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could… | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could… | |
| Analizada | Alta (7.5) | 0.27% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering. | |
| Analizada | Crítica (9.8) | 0.40% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Alta (8.5) | 0.15% | — | Microsoft VFS FOR GITAI | 21/1/2026 | 17/6/2026 | VFS for Git 1.0.21014.1 contains an unquoted service path vulnerability in the GVFS.Service Windows service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem privileges during… | |
| Aplazada | Alta (8.5) | 0.15% | — | Fspro Event LOG ExplorerAI | 21/1/2026 | 17/6/2026 | Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with… | |
| Aplazada | Alta (8.4) | 0.16% | — | Fsas Technologies Serverview Agents FOR WindowsAI | 21/1/2026 | 17/6/2026 | The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the administrator privilege when the installer is executed. | |
| Analizada | Baja (2.3) | 0.15% | — | Oracle SUN ZFS Storage Appliance KIT | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle… | |
| Analizada | Baja (2.9) | 0.53% | — | Rustfs | 16/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid… | |
| Analizada | Media (4.8) | 0.27% | — | Lakefs | 15/1/2026 | 17/6/2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised… |