Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.34%—Powerdns Recursor9/2/202617/6/2026
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
AnalizadaMedia (6.5)0.14%—Powerdns Recursor9/2/202617/6/2026
Crafted delegations or IP fragments can poison cached delegations in Recursor.
AnalizadaAlta (8.2)0.30%—Powerdns Recursor9/2/202617/6/2026
Crafted delegations or IP fragments can poison cached delegations in Recursor.
AplazadaAlta (8.7)0.45%—Dbpower C300 HD CameraAI7/2/202617/6/2026
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the…
ModificadaCrítica (9.8)5.8%—Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR ARM 64 EUS+56/2/202615/7/2026
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving…
AnalizadaMedia (6)0.17%—IBM Powervm Hypervisor2/2/202617/6/2026
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.
AnalizadaBaja (3.3)0.13%—IBM Powervm Hypervisor2/2/202617/6/2026
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.
AnalizadaMedia (6.8)0.10%—Icinga Powershell Framework29/1/202617/6/2026
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of…
AplazadaCrítica (9.2)0.29%—Cardboardpowered CardboardAI27/1/202617/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before 1.21.4.
AnalizadaMedia (4.8)0.17%—Dell Powerscale Onefs22/1/202617/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could…
AnalizadaMedia (5.5)0.13%—Dell Powerscale Onefs22/1/202617/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could…
AnalizadaAlta (7.5)0.27%—Dell Powerscale Onefs22/1/202617/6/2026
Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
AnalizadaCrítica (9.8)0.40%—Dell Powerscale Onefs22/1/202617/6/2026
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AplazadaAlta (8.1)0.59%—Qodeinteractive PowerliftAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1.
ModificadaAlta (8.8)0.65%—Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance22/1/202617/6/2026
Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
AnalizadaAlta (8)0.53%—Microsoft Power Apps16/1/202617/6/2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
AplazadaAlta (8.5)0.17%—Acer EpowersvcAI16/1/202617/6/2026
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service…
AnalizadaAlta (8.4)0.35%—Schneider-electric Ecostruxure Power Build - Rapsody15/1/20263/9/2026
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
AnalizadaAlta (8.4)0.16%—Schneider-electric Ecostruxure Power Build - Rapsody15/1/20263/9/2026
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
AnalizadaAlta (8.5)0.31%—Dynojet Power Core15/1/202617/6/2026
Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System…
AplazadaAlta (7.1)0.21%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AnalizadaMedia (6.1)0.18%—Ironmansoftware Powershell Universal7/1/202617/6/2026
Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.
AplazadaAlta (8.4)0.27%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AplazadaAlta (7.1)0.21%—ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI7/1/202617/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
AnalizadaAlta (7.1)0.30%—Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance6/1/20267/10/2026
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.