Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.1%💥 ExploitPowerjob10/10/202517/6/2026
A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
AnalizadaMedia (4.4)0.13%—Dell Powerscale Onefs8/10/202517/6/2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.
AnalizadaMedia (4.9)0.31%—Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+10825/9/202517/6/2026
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (7.5)0.41%—Dell Powerscale Onefs25/9/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaMedia (6.5)0.22%—Portfolio-elementorAIPwrplugins PowerfolioAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Diego Pereira PowerFolio portfolio-elementor allows Stored XSS.This issue affects PowerFolio: from n/a through <= 3.2.1.
AplazadaBaja (3.7)0.29%—Nghttp2AIPowerdns DnsdistAI18/9/202517/6/2026
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.
En análisisMedia (5.1)0.13%—IBM Powervm Hypervisor14/9/202517/6/2026
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
AnalizadaMedia (4.4)0.11%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed…
AnalizadaAlta (7.8)0.15%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaAlta (7.8)0.10%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (4.4)0.16%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaAlta (7.8)0.53%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
AnalizadaMedia (6.7)0.46%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
AnalizadaAlta (7.8)0.13%—Dell Powerprotect Data Manager10/9/202517/6/2026
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AplazadaMedia (6.4)0.24%—Powerpack Elementor AddonsAI10/9/202517/6/2026
The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaAlta (7.8)0.60%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint9/9/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7)0.33%—Microsoft PowershellMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+99/9/202517/6/2026
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.7)0.13%—Dell Powerscale Onefs8/9/202517/6/2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AplazadaMedia (6)0.13%—AMD Power Management FirmwareAI6/9/202517/6/2026
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.
AplazadaMedia (4.4)0.14%—AMD Power Management FirmwareAIAMD AgesaAI6/9/202517/6/2026
Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
AplazadaCrítica (9.4)0.16%—Sunpower Pvs6AI2/9/202517/6/2026
The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform…
AnalizadaMedia (6.9)0.11%—Tomtretbar Dell Powerscale28/8/202525/9/2026
Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.
AplazadaCrítica (9.8)0.66%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system…
AplazadaCrítica (10)0.80%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code…
AnalizadaMedia (5.5)0.14%—Dell Poweredge R7425 FirmwareDell Poweredge R7415 FirmwareDell Poweredge R6415 Firmware14/8/202517/6/2026
Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.