Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.26%—Dell Powerscale Onefs4/6/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.
AnalizadaMedia (6.1)0.41%—Fudugo FS Product Inquiry4/6/202417/6/2026
The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks
AnalizadaAlta (8.2)0.48%—Fudugo FS Product Inquiry4/6/202417/6/2026
The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users
AnalizadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2053/6/202417/6/2026
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
AnalizadaMedia (6.5)2.3%—Zohocorp Manageengine Adselfservice Plus27/5/202417/6/2026
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
AnalizadaMedia (6.5)0.68%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.
AnalizadaMedia (5.5)0.21%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaAlta (7.5)0.44%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.
AnalizadaMedia (6.7)0.26%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
AnalizadaAlta (7.5)0.92%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (4.4)0.22%—Dell Powerscale Onefs14/5/202417/6/2026
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2326/5/202417/6/2026
Memory corruption when the payload received from firmware is not as per the expected protocol size.
AplazadaCrítica (9.8)0.83%—E-webinformationco Fs-ezviewer WEBAI29/4/202417/6/2026
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP…
AplazadaAlta (7.3)0.78%—Nokia C200AINokia C100AITracfone TfstatusAI22/4/202417/6/2026
Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection…
AplazadaAlta (8.7)0.55%—Microchip Mpfs2AI18/4/202417/6/2026
The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves…
AnalizadaMedia (6.5)0.22%—Oracle ZFS Storage Appliance KIT16/4/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS…
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+2981/4/202417/6/2026
Memory corruption in SPS Application while requesting for public key in sorter TA.
AnalizadaAlta (7.5)0.32%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.
AnalizadaAlta (7.8)0.11%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
AnalizadaAlta (7.5)0.59%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6)0.19%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
AnalizadaMedia (6)0.19%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
AnalizadaMedia (6.7)0.16%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
AnalizadaMedia (5.5)0.16%—Dell Powerscale Onefs28/3/202417/6/2026
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
AnalizadaCrítica (9.1)0.69%—Wolfssl25/3/202417/6/2026
Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length.