Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.22% | — | Oracle ZFS Storage Appliance KIT | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Analizada | Alta (8.8) | 1.4% | — | Dell Powermax EEMDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 28/3/2024 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity. | |
| Analizada | Alta (8.8) | 1.4% | — | Dell Powermax EEMDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 28/3/2024 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity. | |
| Aplazada | Media (4.9) | 0.90% | — | Sonicwall Email Security ApplianceAI | 14/3/2024 | 17/6/2026 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system. | |
| Analizada | Crítica (9.8) | 0.99% | — | Veritas NetbackupVeritas Netbackup Appliance | 7/3/2024 | 17/6/2026 | In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file. | |
| Analizada | Alta (7.5) | 0.85% | — | IBM MQIBM MQ Appliance | 3/3/2024 | 17/6/2026 | IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279. | |
| Modificada | Media (4.3) | 0.38% | — | Oracle ZFS Storage Appliance KIT | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of… | |
| Modificada | Media (4.4) | 0.18% | — | Oracle ZFS Storage Appliance KIT | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Modificada | Baja (2.3) | 0.19% | — | Oracle ZFS Storage Appliance KIT | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Modificada | Crítica (9.8) | 0.71% | 💥 PoC | Cisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware | 10/1/2024 | 17/6/2026 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | |
| Modificada | Media (6.8) | 0.61% | — | LinotpLinotp Virtual Appliance | 19/12/2023 | 17/6/2026 | Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity… | |
| Modificada | Alta (7.5) | 1.3% | — | IBM MQ Appliance | 18/12/2023 | 17/6/2026 | IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536. | |
| Modificada | Alta (7.5) | 0.76% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit this vulnerability leading to obtain sensitive information that may aid in further attacks. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system. | |
| Modificada | Media (4.9) | 0.59% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system. | |
| Modificada | Alta (7.5) | 0.92% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 14/12/2023 | 17/6/2026 | Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system. | |
| Modificada | Media (4.3) | 0.41% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 12/12/2023 | 11/8/2026 | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the… | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+122 | 8/12/2023 | 17/6/2026 | Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Modificada | Media (6.1) | 0.43% | — | Sophos Email Appliance | 30/11/2023 | 17/6/2026 | A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. | |
| Modificada | Media (5.5) | 0.24% | — | Tribe29 Checkmk Appliance Firmware | 27/11/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files. | |
| Modificada | Alta (7.8) | 0.18% | — | IBM MQ Appliance | 3/11/2023 | 17/6/2026 | IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535. | |
| Modificada | Media (6.1) | 0.38% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a… |