Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (10)0.53%—Microchip Maxview Storage Manager8/1/202417/6/2026
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched…
ModificadaCrítica (9.8)0.50%—IBM Storage Fusion HCI8/1/202417/6/2026
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.2)1.8%—Dell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management CenterDell EMC Data Domain OS+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying…
ModificadaMedia (6.1)0.76%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM…
ModificadaAlta (7.8)0.22%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
ModificadaMedia (4.3)0.57%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized…
ModificadaMedia (6.7)0.62%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by…
ModificadaMedia (6.7)0.29%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the…
ModificadaAlta (7.8)0.60%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with…
ModificadaAlta (7.5)0.71%—IBM Storage Virtualize14/12/202317/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.
ModificadaAlta (7.8)0.19%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+1228/12/202317/6/2026
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
ModificadaAlta (7.2)1.1%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
ModificadaCrítica (9.8)0.90%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
The affected devices use publicly available default credentials with administrative privileges.
ModificadaCrítica (9.1)0.58%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
ModificadaAlta (7.5)0.96%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.
ModificadaMedia (6.5)0.54%💥 PoCVantara Hitachi Network Attached Storage5/12/202317/6/2026
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
ModificadaAlta (7.8)0.18%—Intel Rapid Storage Technology14/11/202317/6/2026
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.6)0.26%—Intel Optane Memory H20 With Solid State Storage FirmwareIntel Optane SSD 905p FirmwareIntel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x Firmware14/11/202317/6/2026
Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
ModificadaAlta (7.8)0.22%—Intel Optane Memory H20 With Solid State Storage FirmwareIntel Optane SSD 900p FirmwareIntel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x Firmware+114/11/202317/6/2026
Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.21%—Intel Optane Memory H20 With Solid State Storage FirmwareIntel Optane SSD 900p FirmwareIntel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x Firmware+114/11/202317/6/2026
Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.6)0.31%—Intel Optane Memory H20 With Solid State Storage FirmwareIntel Optane SSD 900p FirmwareIntel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x Firmware+114/11/202317/6/2026
Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
ModificadaMedia (4.4)0.18%—Intel Optane Memory H20 With Solid State Storage FirmwareIntel Optane SSD 900p FirmwareIntel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x Firmware+114/11/202317/6/2026
Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.5)1.7%—SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+46/11/202317/6/2026
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task,…
ModificadaCrítica (9.8)2.4%—SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+13/11/202317/6/2026
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However,…