Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.22%—Oracle ZFS Storage Appliance KIT16/4/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS…
AnalizadaAlta (8.8)1.4%—Dell Powermax EEMDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance28/3/202417/6/2026
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
AnalizadaAlta (8.8)1.4%—Dell Powermax EEMDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance28/3/202417/6/2026
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
AplazadaMedia (4.9)0.90%—Sonicwall Email Security ApplianceAI14/3/202417/6/2026
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system.
AnalizadaCrítica (9.8)0.99%—Veritas NetbackupVeritas Netbackup Appliance7/3/202417/6/2026
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
AnalizadaAlta (7.5)0.85%—IBM MQIBM MQ Appliance3/3/202417/6/2026
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
ModificadaMedia (4.3)0.38%—Oracle ZFS Storage Appliance KIT17/2/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of…
ModificadaMedia (4.4)0.18%—Oracle ZFS Storage Appliance KIT16/1/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS…
ModificadaBaja (2.3)0.19%—Oracle ZFS Storage Appliance KIT16/1/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS…
ModificadaCrítica (9.8)0.71%💥 PoCCisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware10/1/202417/6/2026
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
ModificadaMedia (6.8)0.61%—LinotpLinotp Virtual Appliance19/12/202317/6/2026
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity…
ModificadaAlta (7.5)1.3%—IBM MQ Appliance18/12/202317/6/2026
IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.
ModificadaAlta (7.5)0.76%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit this vulnerability leading to obtain sensitive information that may aid in further attacks.
ModificadaAlta (7.2)1.7%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
ModificadaAlta (7.2)1.7%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
ModificadaAlta (7.2)1.7%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
ModificadaAlta (7.2)1.7%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
ModificadaMedia (4.9)0.59%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
ModificadaAlta (7.5)0.92%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual ApplianceDell Powermax OS14/12/202317/6/2026
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.
ModificadaMedia (4.3)0.41%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense12/12/202311/8/2026
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the…
ModificadaAlta (7.8)0.19%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+1228/12/202317/6/2026
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
ModificadaMedia (6.1)0.43%—Sophos Email Appliance30/11/202317/6/2026
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.
ModificadaMedia (5.5)0.24%—Tribe29 Checkmk Appliance Firmware27/11/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
ModificadaAlta (7.8)0.18%—IBM MQ Appliance3/11/202317/6/2026
IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.
ModificadaMedia (6.1)0.38%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense1/11/202311/8/2026
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a…