Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.26% | — | Dell Powerscale Onefs | 4/6/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service. | |
| Analizada | Media (6.1) | 0.41% | — | Fudugo FS Product Inquiry | 4/6/2024 | 17/6/2026 | The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks | |
| Analizada | Alta (8.2) | 0.48% | — | Fudugo FS Product Inquiry | 4/6/2024 | 17/6/2026 | The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+205 | 3/6/2024 | 17/6/2026 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | |
| Analizada | Media (6.5) | 2.3% | — | Zohocorp Manageengine Adselfservice Plus | 27/5/2024 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input. | |
| Analizada | Media (6.5) | 0.68% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity. | |
| Analizada | Media (5.5) | 0.21% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.5) | 0.44% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (6.7) | 0.26% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Alta (7.5) | 0.92% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (4.4) | 0.22% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+232 | 6/5/2024 | 17/6/2026 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | |
| Aplazada | Crítica (9.8) | 0.83% | — | E-webinformationco Fs-ezviewer WEBAI | 29/4/2024 | 17/6/2026 | E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP… | |
| Aplazada | Alta (7.3) | 0.78% | — | Nokia C200AINokia C100AITracfone TfstatusAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection… | |
| Aplazada | Alta (8.7) | 0.55% | — | Microchip Mpfs2AI | 18/4/2024 | 17/6/2026 | The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves… | |
| Analizada | Media (6.5) | 0.22% | — | Oracle ZFS Storage Appliance KIT | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+298 | 1/4/2024 | 17/6/2026 | Memory corruption in SPS Application while requesting for public key in sorter TA. | |
| Analizada | Alta (7.5) | 0.32% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Alta (7.5) | 0.59% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (6) | 0.19% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. | |
| Analizada | Media (6) | 0.19% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. | |
| Analizada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Media (5.5) | 0.16% | — | Dell Powerscale Onefs | 28/3/2024 | 17/6/2026 | Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges. | |
| Analizada | Crítica (9.1) | 0.69% | — | Wolfssl | 25/3/2024 | 17/6/2026 | Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length. |