Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.81%—Erofs-utils Project Erofs-utils1/6/202317/6/2026
Desbordamiento de Búfer en la función erofsfsck_dirent_iter en fsck/main.c en erofs-utils v1.6 permite a atacantes remotos ejecutar código arbitrario a través de una imagen del sistema de archivos erofs manipulada.
ModificadaAlta (8.8)5.3%💥 ExploitFS S3900 24t4s Firmware29/5/202317/6/2026
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.
ModificadaAlta (7.5)0.38%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+1852/5/202317/6/2026
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
ModificadaCrítica (9.8)2.4%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
ModificadaAlta (8.8)17%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
ModificadaAlta (7.8)0.08%—Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+21513/4/202317/6/2026
Memory corruption due to double free in core while initializing the encryption key.
ModificadaMedia (6.5)0.51%—Linuxfoundation Cubefs12/4/202317/6/2026
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
ModificadaAlta (7.5)3.5%—Oisf SuricataPfsensePfsense Suricata Package6/4/202317/6/2026
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.
ModificadaAlta (7.5)78%—Zohocorp Manageengine Adselfservice Plus5/4/202317/6/2026
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ModificadaCrítica (9.6)0.67%—Netgate PfsenseNetgate Pfsense Acme Package4/4/202317/6/2026
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
ModificadaMedia (6.5)0.60%—Dell EMC Powerscale Onefs4/4/202317/6/2026
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.
ModificadaAlta (7.8)0.16%—Dell EMC Powerscale Onefs4/4/202317/6/2026
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee.
ModificadaAlta (7.8)0.21%—Dell EMC Powerscale Onefs4/4/202317/6/2026
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.
ModificadaCrítica (9.8)3.6%—Go-fastdfs Project Go-fastdfs2/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit…
ModificadaCrítica (9.1)3.1%—Zohocorp Manageengine Adselfservice Plus23/3/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
ModificadaCrítica (9.8)9.8%💥 ExploitNetgate Pfsense PlusPfsense22/3/202317/6/2026
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
ModificadaAlta (8.8)90%💥 ExploitNetgate Pfsense17/3/202317/6/2026
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
ModificadaMedia (4.8)0.39%—Afsanalytics AFS Analytics15/3/202317/6/2026
Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.
ModificadaAlta (8.8)0.41%—Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+20510/3/202317/6/2026
Memory corruption in modem due to buffer overflow while processing a PPP packet
ModificadaMedia (6.7)0.11%—Dell Powerscale Onefs2/3/202317/6/2026
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.
ModificadaAlta (7.1)0.15%—Dell EMC Powerscale Onefs28/2/202317/6/2026
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service.
ModificadaMedia (6.1)60%—Netgate Pfsense22/2/202317/6/2026
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
ModificadaAlta (7.5)0.91%—Glusterfs21/2/202317/6/2026
In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.
ModificadaAlta (7.5)0.87%—Glusterfs21/2/202317/6/2026
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
ModificadaAlta (7.5)0.58%—Netgear Prosafe Fs726tp Firmware15/2/202317/6/2026
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.