Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Dell Powerscale Onefs | 10/8/2021 | 17/6/2026 | Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege. | |
| Modificada | Alta (8.1) | 0.84% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 5/8/2021 | 17/6/2026 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | |
| Modificada | Alta (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… | |
| Modificada | Media (5.3) | 0.95% | — | Dell Powerscale Onefs | 3/8/2021 | 17/6/2026 | Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses. | |
| Modificada | Media (6.5) | 0.83% | — | Dell EMC Powerscale Onefs | 3/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event. | |
| Modificada | Media (4.4) | 0.22% | — | Dell EMC Powerscale Onefs | 3/8/2021 | 17/6/2026 | Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control. | |
| Modificada | Alta (8.8) | 0.22% | — | Dell Powerscale Onefs | 3/8/2021 | 17/6/2026 | Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest. | |
| Modificada | Alta (8.8) | 0.99% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 29/7/2021 | 17/6/2026 | The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to… | |
| Modificada | Alta (8.8) | 0.59% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 28/7/2021 | 17/6/2026 | Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols. | |
| Modificada | Alta (7.8) | 0.46% | — | Zscaler Client Connector | 15/7/2021 | 17/6/2026 | The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context. | |
| Modificada | Alta (7.8) | 0.32% | — | Zscaler Client Connector | 15/7/2021 | 17/6/2026 | The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges. | |
| Modificada | Crítica (9.8) | 1.9% | — | Zscaler Client Connector | 15/7/2021 | 17/6/2026 | The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges. | |
| Modificada | Media (6.5) | 3.0% | 💥 PoC | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a… | |
| Modificada | Media (6.5) | 0.42% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from… | |
| Modificada | Media (6.3) | 0.60% | — | Redhat 3scale API Management | 2/6/2021 | 17/6/2026 | A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission. | |
| Modificada | Alta (7.3) | 0.76% | — | Redhat 3scaleRedhat 3scale API Management | 1/6/2021 | 17/6/2026 | It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks. | |
| Modificada | Alta (7.8) | 0.33% | — | IBM Spectrum Scale | 1/6/2021 | 17/6/2026 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entire system with root… | |
| Modificada | Media (5.4) | 0.52% | — | Redhat 3scaleRedhat 3scale API Management | 26/5/2021 | 17/6/2026 | A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected. | |
| Modificada | Crítica (9.1) | 0.68% | — | IBM Power9 System FirmwareIBM Scale-out LC System Firmware | 26/5/2021 | 17/6/2026 | IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process. | |
| Modificada | Alta (8.8) | 0.58% | — | Redhat 3scale | 26/5/2021 | 17/6/2026 | A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks. | |
| Modificada | Media (6.7) | 0.26% | — | IBM Spectrum Scale | 25/5/2021 | 17/6/2026 | IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883. | |
| Modificada | Media (6.7) | 0.27% | — | Dell EMC Powerscale Onefs | 6/5/2021 | 17/6/2026 | Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | |
| Modificada | Media (6.7) | 0.27% | — | Dell EMC Powerscale Onefs | 6/5/2021 | 17/6/2026 | Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | |
| Modificada | Alta (7.8) | 1.2% | — | IBM Spectrum Scale | 27/4/2021 | 17/6/2026 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Spectrum Scale | 27/4/2021 | 17/6/2026 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… |