Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.48% | — | IBM Storage Scale | 13/8/2026 | 17/8/2026 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Azure Storage Explorer | 11/8/2026 | 17/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 2.3% | — | Dell Virtual Storage Integrator | 6/8/2026 | 7/8/2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's… | |
| Analizada | Crítica (9.8) | 0.62% | — | Dell Virtual Storage Integrator | 6/8/2026 | 7/8/2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered… | |
| Pendiente de análisis | Crítica (9.5) | 2.1% | 💥 Exploit | Rails Action PackAILibvipsAIRubyonrails Active StorageAI | 30/7/2026 | 10/9/2026 | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured… | |
| Analizada | Alta (8.7) | 0.52% | — | Progress Sharefile Storage Zones Controller | 21/7/2026 | 3/9/2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Storage Protect | 17/7/2026 | 11/8/2026 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Analizada | Crítica (9.8) | 0.52% | — | Proxmox Libpve-storage-perl | 17/7/2026 | 11/8/2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| Aplazada | Alta (8.5) | 0.16% | — | Gigabyte Control CenterAIGigabyte Mbstorage DramAI | 13/7/2026 | 14/7/2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and… | |
| Analizada | Crítica (10) | 0.64% | — | Appium/storage-plugin | 8/7/2026 | 26/8/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path… | |
| Pendiente de análisis | Media (6.9) | 0.47% | 💥 PoC | Microsoft Azure Blob StorageAI | 3/7/2026 | 6/7/2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container. | |
| Aplazada | Crítica (10) | 4.4% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary… | |
| Aplazada | Crítica (10) | 4.2% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is… | |
| Aplazada | Crítica (9.2) | 0.55% | — | Storage Concentrator ScvmAIStonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract… | |
| Aplazada | Crítica (9.3) | 0.18% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database… | |
| Aplazada | Media (5.1) | 0.33% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the… | |
| Aplazada | Alta (8.3) | 0.35% | — | Hitachi Virtual Storage Platform E390AIHitachi Virtual Storage Platform E590AIHitachi Virtual Storage Platform E790AIHitachi Virtual Storage Platform E990AI+23 | 29/6/2026 | 29/6/2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H,… | |
| Aplazada | Media (6.8) | 0.38% | — | Hitachi Storage NavigatorAIHitachi Virtual Storage PlatformAIHitachi DkcmainAIHitachi SVPAI | 29/6/2026 | 29/9/2026 | Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, before DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi Virtual Storage… | |
| Aplazada | Baja (3.7) | 0.13% | — | Hitachi Virtual Storage Platform ONE BlockAI | 29/6/2026 | 29/9/2026 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. | |
| En análisis | Crítica (9.1) | 0.63% | — | IBM Storage Protect | 22/6/2026 | 26/6/2026 | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential… | |
| Aplazada | Alta (8.6) | 0.46% | — | Hitachi Virtual Storage PlatformAI | 19/6/2026 | 29/9/2026 | DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN… | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | Purestorage Flasharray PurityAI | 9/6/2026 | 23/7/2026 | A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges. | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Purestorage Flasharray PurityAI | 9/6/2026 | 23/7/2026 | A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges. | |
| Aplazada | Alta (7.5) | 0.67% | — | 6storage RentalsAI | 9/6/2026 | 23/7/2026 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and… | |
| Modificada | Media (5.5) | 0.09% | — | Synology Storage Manager | 27/5/2026 | 17/6/2026 | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. |