Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.62% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. | |
| Analizada | Crítica (9.8) | 0.58% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. | |
| Analizada | Media (6.5) | 0.56% | — | IBM Spectrum Virtualize | 5/3/2024 | 17/6/2026 | LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Spectrum Scale Container Native Storage Access | 17/2/2024 | 17/6/2026 | IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. | |
| Analizada | Media (6.5) | 0.14% | — | IBM Spectrum Scale Container Native Storage Access | 17/2/2024 | 17/6/2026 | IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811. | |
| Modificada | Alta (7.5) | 0.61% | — | IBM Spectrum Protect Plus | 2/2/2024 | 17/6/2026 | IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599. | |
| Modificada | Alta (7.8) | 0.15% | — | Siemens Spectrum Power 7 | 9/1/2024 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute several entries as root user. This could allow an authenticated local attacker to inject arbitrary code and gain root access. | |
| Modificada | Alta (7.5) | 0.41% | — | IBM Spectrum Scale | 14/12/2023 | 17/6/2026 | IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080. | |
| Modificada | Alta (7.8) | 0.16% | — | Siemens Spectrum Power 7 | 14/9/2023 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges. | |
| Modificada | Crítica (9.1) | 0.70% | — | Precisely Spectrum Spatial Analyst | 31/7/2023 | 17/6/2026 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF). | |
| Modificada | Media (5.3) | 0.90% | — | Precisely Spectrum Spatial Analyst | 31/7/2023 | 17/6/2026 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal. | |
| Modificada | Alta (7.8) | 0.18% | — | IBM Spectrum Scale Container Native Storage Access | 31/7/2023 | 17/6/2026 | IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without proper security context settings configured. IBM X-Force ID: 238941. | |
| Modificada | Media (4.7) | 0.13% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual Environments | 19/7/2023 | 17/6/2026 | IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Spectrum Protect Backup-archive Client | 22/6/2023 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | |
| Modificada | Media (4.9) | 0.57% | — | IBM Spectrum Protect | 12/5/2023 | 17/6/2026 | IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325. | |
| Modificada | Alta (7.5) | 0.65% | — | IBM Spectrum Virtualize | 11/5/2023 | 17/6/2026 | IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518. | |
| Modificada | Media (5.5) | 0.21% | — | IBM Elastic Storage SystemIBM Spectrum Scale | 5/5/2023 | 17/6/2026 | IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187. | |
| Modificada | Alta (7.8) | 0.19% | — | IBM Spectrum Scale Container Native Storage Access | 29/4/2023 | 17/6/2026 | IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810. | |
| Modificada | Alta (8.4) | 0.20% | — | IBM Spectrum Scale Container Native Storage Access | 26/4/2023 | 17/6/2026 | IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID: 237815. | |
| Modificada | Alta (8.2) | 0.35% | — | IBM Spectrum Scale | 15/3/2023 | 17/6/2026 | A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695. | |
| Modificada | Media (6.1) | 0.41% | — | IBM Spectrum Symphony | 10/3/2023 | 17/6/2026 | IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 247030. | |
| Modificada | Alta (8.8) | 0.61% | — | IBM Spectrum Virtualize | 22/2/2023 | 17/6/2026 | An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847. | |
| Modificada | Media (6.5) | 0.63% | — | IBM Spectrum Virtualize | 22/2/2023 | 17/6/2026 | IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540. | |
| Modificada | Media (6.5) | 0.99% | — | IBM Elastic Storage SystemIBM Spectrum Scale | 12/2/2023 | 17/6/2026 | IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539. | |
| Modificada | Media (5.9) | 0.55% | — | IBM Spectrum Virtualize | 19/1/2023 | 17/6/2026 | IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-the-middle techniques. IBM X-Force ID: 235408. |