Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | Powerdns Recursor | 9/2/2026 | 17/6/2026 | Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor. | |
| Analizada | Media (6.5) | 0.14% | — | Powerdns Recursor | 9/2/2026 | 17/6/2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. | |
| Analizada | Alta (8.2) | 0.30% | — | Powerdns Recursor | 9/2/2026 | 17/6/2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. | |
| Aplazada | Alta (8.7) | 0.45% | — | Dbpower C300 HD CameraAI | 7/2/2026 | 17/6/2026 | DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the… | |
| Modificada | Crítica (9.8) | 5.8% | — | Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR ARM 64 EUS+5 | 6/2/2026 | 15/7/2026 | A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving… | |
| Analizada | Media (6) | 0.17% | — | IBM Powervm Hypervisor | 2/2/2026 | 17/6/2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures. | |
| Analizada | Baja (3.3) | 0.13% | — | IBM Powervm Hypervisor | 2/2/2026 | 17/6/2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations. | |
| Analizada | Media (6.8) | 0.10% | — | Icinga Powershell Framework | 29/1/2026 | 17/6/2026 | The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Cardboardpowered CardboardAI | 27/1/2026 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before 1.21.4. | |
| Analizada | Media (4.8) | 0.17% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could… | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could… | |
| Analizada | Alta (7.5) | 0.27% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering. | |
| Analizada | Crítica (9.8) | 0.40% | — | Dell Powerscale Onefs | 22/1/2026 | 17/6/2026 | Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Alta (8.1) | 0.59% | — | Qodeinteractive PowerliftAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Modificada | Alta (8.8) | 0.65% | — | Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance | 22/1/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (8) | 0.53% | — | Microsoft Power Apps | 16/1/2026 | 17/6/2026 | Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. | |
| Aplazada | Alta (8.5) | 0.17% | — | Acer EpowersvcAI | 16/1/2026 | 17/6/2026 | Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service… | |
| Analizada | Alta (8.4) | 0.35% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. | |
| Analizada | Alta (8.4) | 0.16% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody. | |
| Analizada | Alta (8.5) | 0.31% | — | Dynojet Power Core | 15/1/2026 | 17/6/2026 | Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System… | |
| Aplazada | Alta (7.1) | 0.21% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Analizada | Media (6.1) | 0.18% | — | Ironmansoftware Powershell Universal | 7/1/2026 | 17/6/2026 | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. | |
| Aplazada | Alta (8.4) | 0.27% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Alta (7.1) | 0.21% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Analizada | Alta (7.1) | 0.30% | — | Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance | 6/1/2026 | 7/10/2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control. |