Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.5) | 2.3% | — | Microsoft .netMicrosoft Powershell | 14/4/2026 | 15/7/2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Crítica (9) | 0.77% | — | Microsoft Power Apps | 14/4/2026 | 17/6/2026 | Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Powershell | 14/4/2026 | 17/6/2026 | Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (5.3) | 0.24% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests. | |
| Analizada | Media (6.9) | 0.19% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. | |
| Analizada | Media (5.3) | 0.17% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload. | |
| Analizada | Media (6.9) | 0.27% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints. | |
| Analizada | Baja (2.4) | 0.10% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. | |
| Analizada | Media (5.3) | 0.23% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. | |
| Analizada | Media (6.9) | 0.20% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload. | |
| Aplazada | Alta (7.5) | 0.36% | — | UI Unifi Play PowerampAIUI Unifi Play Audio PortAI | 13/4/2026 | 17/6/2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version… | |
| Aplazada | Alta (7.5) | 0.43% | — | UI Unifi Play PowerampAIUI Unifi Play Audio PortAI | 13/4/2026 | 17/6/2026 | An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version… | |
| Aplazada | Crítica (9.8) | 0.42% | — | UI Unifi Play PowerampAIUI Unifi Play Audio PortAI | 13/4/2026 | 17/6/2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play… | |
| Aplazada | Crítica (9.8) | 1.1% | — | UI Unifi Play PowerampAIUI Unifi Play Audio PortAI | 13/4/2026 | 17/6/2026 | A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version… | |
| Aplazada | Crítica (9.8) | 0.77% | — | UI Unifi Play PowerampAIUI Unifi Play Audio PortAI | 13/4/2026 | 17/6/2026 | A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | 💥 PoC | Entechtaiwan PowerstripAI | 9/4/2026 | 17/6/2026 | The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical memory into their address space and modify critical kernel structures. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Powerscale Onefs | 8/4/2026 | 24/7/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (4.4) | 0.16% | — | Dell Powerscale Onefs | 8/4/2026 | 24/7/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerprotect Data Manager | 8/4/2026 | 24/7/2026 | Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (6.4) | 0.26% | — | Blubrry PowerpressAI | 8/4/2026 | 25/7/2026 | The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (6.9) | 0.52% | — | PowerjobAI | 7/4/2026 | 24/7/2026 | A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | PowerjobAI | 7/4/2026 | 24/7/2026 | A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql… | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Analizada | Media (6.8) | 0.25% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user. |