Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.27% | — | Dell Elastic Cloud Storage | 4/5/2023 | 17/6/2026 | DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request. | |
| Modificada | Alta (7.5) | 1.3% | — | Dell EMC Elastic Cloud Storage | 2/9/2020 | 17/6/2026 | Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system. | |
| Modificada | Media (4.8) | 0.62% | — | Dell EMC Elastic Cloud Storage | 6/2/2020 | 17/6/2026 | Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by… | |
| Modificada | Crítica (9.8) | 1.9% | — | Dell EMC Elastic Cloud Storage | 27/9/2019 | 17/6/2026 | Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts. | |
| Modificada | Crítica (9.8) | 4.0% | — | Dellemc Elastic Cloud Storage | 3/7/2018 | 17/6/2026 | Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying specially crafted S3 requests. | |
| Modificada | Crítica (9.8) | 2.1% | — | Dell Elastic Cloud Storage | 3/10/2017 | 17/6/2026 | EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system. | |
| Modificada | Media (4.3) | 1.4% | — | Ctera Cloud Storage OS | 11/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the description in a project folder. |