Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.2%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.
ModificadaAlta (8.8)1.6%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted…
ModificadaAlta (7.2)0.99%—Oretnom23 Simple Cold Storage Management System6/10/202217/6/2026
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=.
ModificadaAlta (7.2)1.0%—Oretnom23 Simple Cold Storage Management System6/10/202217/6/2026
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
ModificadaAlta (7.2)1.0%—Oretnom23 Simple Cold Storage Management System6/10/202217/6/2026
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id=.
ModificadaAlta (7.2)1.0%—Oretnom23 Simple Cold Storage Management System6/10/202217/6/2026
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
ModificadaAlta (7.2)1.0%—Oretnom23 Simple Cold Storage Management System6/10/202217/6/2026
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
ModificadaAlta (8.8)0.55%—Hitachi Storage Plug-in6/10/202217/6/2026
Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.
ModificadaMedia (5.4)0.49%—Storage Unit Rental Management System Project Storage Unit Rental Management System16/9/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , Apache 2.4.14, SURMS V 1.0 via the Add New Tenant List Rent List form.
ModificadaAlta (8.8)1.3%—Hitachi Raid Manager Storage Replication Adapter6/9/202217/6/2026
OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows…
ModificadaMedia (6.5)0.88%—Hitachi Raid Manager Storage Replication Adapter6/9/202217/6/2026
Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior…
ModificadaMedia (6.6)0.72%—Openstack KeystoneRedhat Openstack PlatformRedhat QuayRedhat Storage1/9/202217/6/2026
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
ModificadaMedia (6.5)1.3%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.
ModificadaAlta (8.8)1.4%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.
ModificadaCrítica (9.8)0.97%—Dell Smartfabric Storage Software30/8/202217/6/2026
SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system.
ModificadaMedia (6.5)0.56%—Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+325/8/202217/6/2026
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
AnalizadaMedia (6.5)2.2%—SambaRedhat StorageFedoraproject Fedora23/8/202217/6/2026
MaxQueryDuration not honoured in Samba AD DC LDAP
ModificadaMedia (6.5)0.73%—Netapp Storagegrid10/8/202217/6/2026
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content.
ModificadaCrítica (9.8)19%💥 PoCZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+145/8/202214/7/2026
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the…
ModificadaMedia (6.5)1.4%—Synology Storage Analyzer3/8/202217/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.
ModificadaCrítica (9.8)0.81%—S3-kilatstorage Project S3-kilatstorage2/8/202217/6/2026
This affects all versions of package s3-kilatstorage.
ModificadaAlta (7.5)7.6%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+327/7/202217/6/2026
nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.
ModificadaCrítica (9.1)1.2%—Linuxfoundation CephRedhat Ceph StorageFedoraproject Fedora25/7/202217/6/2026
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed…
ModificadaCrítica (9.8)0.96%—Google-cloudstorage-commands Project Google-cloudstorage-commands25/7/202217/6/2026
This affects all versions of package google-cloudstorage-commands.
ModificadaBaja (3.4)0.22%—Oracle ZFS Storage Appliance KIT19/7/202217/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS…