Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.46% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (6.7) | 0.14% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, elevation of privileges, and information… | |
| Analizada | Media (6.7) | 0.14% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, elevation of privileges, and information… | |
| Analizada | Alta (7.8) | 0.09% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.7) | 0.13% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to code execution, denial of service, elevation of privileges, and… | |
| Modificada | Media (6.7) | 0.11% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setting vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |
| Analizada | Media (6.7) | 0.13% | — | Dell Powerscale Onefs | 4/3/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Modificada | Media (6.5) | 0.22% | — | Ironmansoftware Powershell Universal | 27/2/2026 | 17/6/2026 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials | |
| Analizada | Media (6.5) | 0.20% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service of a Dell Enterprise Support connection. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.29% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |
| Analizada | Alta (8.1) | 0.53% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files. | |
| Analizada | Media (6.5) | 0.40% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (8.1) | 0.46% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. | |
| Analizada | Alta (8.8) | 0.51% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files. | |
| Analizada | Alta (8.8) | 0.43% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (4.7) | 0.18% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |
| Aplazada | Media (5.4) | 0.29% | — | Dell Unisphere FOR PowermaxAI | 17/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in… | |
| Aplazada | Media (5.4) | 0.17% | — | Dell Unisphere FOR Powermax VappAI | 17/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript… | |
| Aplazada | Alta (7.2) | 0.10% | — | AMD Power Management FirmwareAI | 12/2/2026 | 17/6/2026 | An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.19% | — | Solax Power PocketAISolax CloudAI | 12/2/2026 | 17/6/2026 | When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the… | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 10/2/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.57% | — | Modery Powerdocu | 9/2/2026 | 17/6/2026 | PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files, allowing an attacker to instantiate arbitrary… | |
| Analizada | Media (5.3) | 0.45% | — | Powerdns Recursor | 9/2/2026 | 17/6/2026 | Crafted zones can lead to increased incoming network traffic. |