Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

703 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.15%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.
ModificadaMedia (6.5)0.40%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.
ModificadaMedia (6.7)0.17%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
ModificadaMedia (6.7)0.17%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.
ModificadaMedia (4.3)0.38%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
ModificadaAlta (7.8)0.17%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure.
ModificadaAlta (7.8)0.15%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
ModificadaMedia (6.7)0.17%—Dell Powerscale Onefs16/8/202317/6/2026
Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.
ModificadaMedia (6.5)0.32%—Mariadb Maxscale14/8/202317/6/2026
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.
ModificadaAlta (7.8)0.18%—IBM Spectrum Scale Container Native Storage Access31/7/202317/6/2026
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without proper security context settings configured. IBM X-Force ID: 238941.
ModificadaAlta (8)1.3%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Privilege Escalation to root administrator (nsroot)
ModificadaMedia (6.1)2.6%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Reflected Cross-Site Scripting (XSS)
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/20235/8/2026
Unauthenticated remote code execution
ModificadaAlta (8.8)0.90%—Veritas Infoscale Operations Manager17/7/202317/6/2026
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
ModificadaMedia (6.3)0.29%—Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+426/6/202317/6/2026
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
ModificadaAlta (7.5)0.62%—Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+426/6/202317/6/2026
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
ModificadaMedia (6.1)0.55%—Zscaler Client Connector22/6/202317/6/2026
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
ModificadaMedia (6.1)0.45%—Zscaler Client Connector22/6/202317/6/2026
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
ModificadaAlta (7)0.96%💥 ExploitNokia Asika Airscale Firmware16/6/202317/6/2026
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default)…
ModificadaAlta (7.8)0.10%—Nokia Asika Airscale Firmware16/6/202317/6/2026
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network…
ModificadaBaja (2.8)0.19%—Nokia Asika Airscale Firmware16/6/202317/6/2026
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to…
ModificadaAlta (7.8)0.14%—Nokia Asika Airscale Firmware16/6/202317/6/2026
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources.
ModificadaCrítica (9.8)0.58%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the…
ModificadaAlta (7.2)0.70%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage…
ModificadaMedia (5.5)0.21%—IBM Elastic Storage SystemIBM Spectrum Scale5/5/202317/6/2026
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.
Orbitaley — Vulnerabilidades