Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.47%—Lucky Lm-520-scAILucky Lm-520-fscAILucky Lm-520-fsc-samAI9/6/202517/6/2026
A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may…
AplazadaAlta (8.7)0.58%—Tar-fsAI2/6/202517/6/2026
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.
AplazadaAlta (8.8)0.43%—Offsprout Page BuilderAI31/5/202517/6/2026
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() function in versions 2.2.1 to 2.15.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to read, create, update or delete…
AplazadaAlta (7.1)0.28%—Reifsnyderb Document Management SystemAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System dms allows Reflected XSS.This issue affects Document Management System: from n/a through <= 1.24.
AplazadaAlta (7.1)0.22%—Thewebhunter Offset WritingAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in twh offset writing allows Reflected XSS.This issue affects offset writing: from n/a through 1.2.
AnalizadaMedia (6.5)0.25%—Seaweedfs16/5/202517/6/2026
seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.
AnalizadaAlta (7.5)0.48%—Dell Powerscale Onefs15/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (5.4)1.3%—Netgate Pfsense CENetgate Pfsense Plus14/5/20255/7/2026
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and…
AnalizadaAlta (8.8)12%—Netgate Pfsense CENetgate Pfsense Plus14/5/202517/6/2026
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN…
AnalizadaMedia (5.4)8.5%—Netgate Pfsense CENetgate Pfsense Plus14/5/202517/6/2026
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
AnalizadaAlta (8.1)45%—Zohocorp Manageengine Adselfservice Plus14/5/202517/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
AnalizadaMedia (5.5)0.22%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6.3)0.16%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.
AplazadaBaja (2.9)0.17%—ObfstrAI2/5/202517/6/2026
In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.
AplazadaAlta (7.1)0.14%—Offshorewebmaster Availability CalendarAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4.
AplazadaMedia (4.7)0.14%—Arctera Veritas Data InsightAIDell Isilon OnefsAI16/4/202517/6/2026
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
AplazadaAlta (8.3)0.31%—Fs-code FS PosterAI16/4/202517/6/2026
Missing Authorization vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5.8.
AplazadaAlta (7.1)0.23%—Fs-code FS PosterAI15/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster fs-poster allows Reflected XSS.This issue affects FS Poster: from n/a through <= 6.5.8.
AnalizadaCrítica (9.8)0.47%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.
AnalizadaAlta (7.5)0.45%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
AnalizadaBaja (3.1)0.25%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.
AnalizadaAlta (7)0.15%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
AnalizadaBaja (3.3)0.16%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
AnalizadaMedia (6.5)0.37%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
AplazadaMedia (5.4)0.15%—Elfsight Testimonials SliderAI31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Cross Site Request Forgery.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1.