Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.5% | — | Theeventscalendar THE Events CalendarAI | 12/9/2026 | 14/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse,… | |
| Analizada | Media (6.7) | 0.53% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting… | |
| Analizada | Baja (3.5) | 0.18% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. | |
| Analizada | Media (5.4) | 0.39% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering. | |
| Pendiente de análisis | Media (5) | 0.20% | — | Okta Privileged Access ClientAIOkta ScaleftAI | 8/9/2026 | 10/9/2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended… | |
| Aplazada | Baja (2.7) | 0.32% | — | Theeventscalendar THE Events CalendarAI | 5/9/2026 | 8/9/2026 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Theeventscalendar THE Events CalendarAI | 24/8/2026 | 26/8/2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.66% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | |
| Pendiente de análisis | Crítica (9.1) | 0.53% | — | Zscaler Client ConnectorAIZscaler Client Connector PortalAI | 24/8/2026 | 28/8/2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |
| Analizada | Crítica (9.3) | 23% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/8/2026 | 10/9/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | |
| Pendiente de análisis | Alta (8.8) | 3.2% | — | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 19/8/2026 | 1/9/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (7.8) | 0.65% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.1) | 0.16% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (7.8) | 0.65% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.3) | 0.72% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Baja (3.3) | 0.18% | — | Dell Objectscale | 17/8/2026 | 19/8/2026 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.5) | 0.16% | — | IBM Storage Scale | 13/8/2026 | 18/8/2026 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM… | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Storage Scale | 13/8/2026 | 17/8/2026 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI. | |
| Analizada | Alta (7.1) | 0.44% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and… | |
| Analizada | Alta (7.2) | 0.53% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit… |