Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 2.7% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By… | |
| Modificada | Media (4.8) | 0.45% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter… | |
| Modificada | Alta (8.8) | 0.66% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+22 | 4/3/2022 | 17/6/2026 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable… | |
| Modificada | Alta (7) | 0.43% | — | Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+28 | 3/3/2022 | 17/6/2026 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root. | |
| Modificada | Media (5.5) | 0.23% | — | IBM Spectrum Scale | 1/3/2022 | 17/6/2026 | A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 191599. | |
| Modificada | Alta (7.1) | 1.7% | — | Linux KernelRedhat 3scaleRedhat Virtualization HostFedoraproject Fedora+15 | 16/2/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality,… | |
| Modificada | Media (4.3) | 0.35% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events | |
| Modificada | Media (6.1) | 0.81% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues | |
| Modificada | Alta (7.5) | 1.1% | — | Dell Powerscale Onefs | 21/12/2021 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the factors of authentication. | |
| Modificada | Media (5.5) | 0.25% | — | Dell EMC Powerscale Onefs | 23/11/2021 | 17/6/2026 | Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files. | |
| Modificada | Media (4.4) | 0.24% | — | IBM Spectrum Scale | 16/11/2021 | 17/6/2026 | IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209164. | |
| Modificada | Media (6.8) | 0.25% | — | Dell EMC Powerscale Nodes A100 FirmwareDell EMC Powerscale Nodes S210 FirmwareDell EMC Powerscale Nodes X410 FirmwareDell EMC Powerscale Nodes H400 Firmware+15 | 12/11/2021 | 17/6/2026 | Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privileges. This also affects Compliance mode and for Compliance mode clusters, is a critical vulnerability. Dell EMC recommends applying the workaround at your earliest opportunity. | |
| Modificada | Media (6.5) | 0.83% | — | Dell EMC Powerscale Onefs | 12/11/2021 | 17/6/2026 | Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of service over SMB. | |
| Modificada | Alta (7.5) | 0.99% | — | Dell EMC Powerscale Onefs | 12/11/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability. This vulnerability is triggered when upgrading from a previous versions. | |
| Modificada | Crítica (9.8) | 1.7% | — | Adaptivescale Lxdui | 3/9/2021 | 17/6/2026 | A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system. | |
| Modificada | Baja (3.3) | 0.20% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to gain access up to 24 bytes of data within the /ifs kernel stack under certain conditions. | |
| Modificada | Alta (8.8) | 0.69% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges. | |
| Modificada | Media (5.5) | 0.18% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster. | |
| Modificada | Media (5.5) | 0.56% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any… | |
| Modificada | Media (6.7) | 0.38% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability… | |
| Modificada | Media (6.7) | 0.24% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to… | |
| Modificada | Media (5.3) | 0.81% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity. | |
| Modificada | Media (6.5) | 0.84% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure. | |
| Modificada | Media (4.3) | 0.57% | — | Dell EMC Powerscale Onefs | 16/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user with ISI_PRIV_LOGIN_PAPI could make un-audited and un-trackable configuration changes to settings that their roles have privileges to change. |