Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.68% | — | Dell Powerstoreos | 21/10/2022 | 17/6/2026 | Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit. | |
| Modificada | Alta (7.8) | 0.35% | — | Dell EMC Powerstore 500t FirmwareDell EMC Powerstore 1200t FirmwareDell EMC Powerstore 3200t FirmwareDell EMC Powerstore 5200t Firmware+1 | 21/7/2022 | 17/6/2026 | Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take… | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Powerstore Command Line Interface | 21/7/2022 | 17/6/2026 | Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell EMC Powerstore 500t FirmwareDell EMC Powerstore 1200t FirmwareDell EMC Powerstore 3200t FirmwareDell EMC Powerstore 5200t Firmware+1 | 21/7/2022 | 17/6/2026 | Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users. | |
| Modificada | Media (6.7) | 0.80% | 💥 PoC | Dell EMC Powerstore 500t FirmwareDell EMC Powerstore 1200t FirmwareDell EMC Powerstore 3200t FirmwareDell EMC Powerstore 5200t Firmware+1 | 21/7/2022 | 17/6/2026 | Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation… | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.40% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.… | |
| Modificada | Alta (8) | 0.60% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used… | |
| Modificada | Media (5.5) | 0.47% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store… | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Alta (7.5) | 1.3% | — | Dell Powerstoreos | 2/6/2022 | 17/6/2026 | Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service. | |
| Modificada | Media (4.4) | 0.20% | — | Dell EMC Powerstore | 19/7/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system directory. | |
| Modificada | Media (6.7) | 0.42% | — | Dell EMC Powerstore | 19/7/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a… | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Media (6.7) | 0.18% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Alta (7.5) | 0.94% | — | Dell EMC Powerstore 1000 FirmwareDell EMC Powerstore 3000 FirmwareDell EMC Powerstore 5000 FirmwareDell EMC Powerstore 7000 Firmware+1 | 6/7/2020 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment. | |
| Modificada | Media (4.3) | 1.0% | — | Webassist Powerstore | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Products_Results.php in PowerStore 3.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_WADAProducts parameter. |