Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.17% | — | Dell Powerprotect Data Manager | 28/4/2025 | 17/6/2026 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Powerprotect Data Manager | 28/4/2025 | 17/6/2026 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Crítica (9.9) | 0.43% | — | Blubrry PowerpressAI | 24/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.This issue affects PowerPress Podcasting: from n/a through <= 11.12.5. | |
| Analizada | Media (5.7) | 0.90% | — | Microsoft Power Automate FOR Desktop | 15/4/2025 | 17/6/2026 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.9) | 0.26% | — | Blubrry Powerpress | 14/4/2025 | 17/6/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (5.3) | 0.32% | — | Powercreator CMSAI | 13/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PowerCreator CMS 1.0. Affected is an unknown function of the file /OpenPublicCourse.aspx. The manipulation of the argument cid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (6.9) | 0.18% | — | Subnet Powersystem CenterAI | 11/4/2025 | 17/6/2026 | Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition. | |
| Aplazada | Media (5.3) | 0.14% | — | Subnet Powersystem CenterAI | 11/4/2025 | 17/6/2026 | Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters. | |
| Analizada | Media (4.9) | 0.33% | — | Dell Powerprotect Cyber Recovery | 11/4/2025 | 17/6/2026 | Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Crítica (9.8) | 0.47% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account. | |
| Analizada | Alta (7.5) | 0.45% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Baja (3.1) | 0.25% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues. | |
| Analizada | Alta (7) | 0.15% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account. | |
| Analizada | Baja (3.3) | 0.16% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (6.5) | 0.37% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Media (4.9) | 0.26% | — | Blubrry PowerpressAI | 9/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.12.6. | |
| Aplazada | Media (6.5) | 0.29% | — | Blubrry Powerpress PodcastingAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.12.5. | |
| Aplazada | Media (6.7) | 0.19% | — | Hgiga PowerstationAI | 8/4/2025 | 17/6/2026 | The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system. | |
| Aplazada | Alta (7.5) | 0.76% | — | Powerdns RecursorAI | 7/4/2025 | 17/6/2026 | An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing… | |
| Analizada | Media (4.7) | 0.29% | — | Dell Unisphere FOR Powermax | 7/4/2025 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,… | |
| Analizada | Alta (8.8) | 0.53% | — | Dell Powerprotect Data DomainDell Data Domain Operating SystemDell Powerprotect Dm5500 Firmware | 3/4/2025 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Modificada | Alta (7.4) | 14% | — | Gnome YelpDebian LinuxRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64+17 | 3/4/2025 | 29/6/2026 | A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. | |
| Aplazada | Alta (7.1) | 0.29% | — | Angelo Mandato Blubrry Powerpress Podcasting Plugin MultisiteAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato Blubrry PowerPress Podcasting plugin MultiSite add-on powerpress-multisite allows Reflected XSS.This issue affects Blubrry PowerPress Podcasting plugin MultiSite add-on: from n/a through <= 0.1.1. | |
| Modificada | Media (6.5) | 0.86% | — | Gnome LibsoupRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Arm64 EUS+17 | 3/4/2025 | 30/6/2026 | A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. | |
| Aplazada | Media (5.1) | 0.80% | — | Legrand SMS PowerviewAI | 31/3/2025 | 17/6/2026 | A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument redirect leads to os command injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about… |