Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+197 | 12/2/2023 | 17/6/2026 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Powerscale Onefs | 11/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (7.5) | 0.43% | — | Dell Powerscale Onefs | 11/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak. | |
| Modificada | Media (4.8) | 0.39% | — | Dell EMC Powerscale Onefs | 10/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields. | |
| Modificada | Media (6.7) | 0.19% | — | Dell EMC Powerscale Onefs | 10/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versiones 8.2.x-9.3.x, contiene un desbordamiento de búfer basado en almacenamiento dinámico. Un usuario local malicioso con privilegios podría explotar esta vulnerabilidad y tomar el control del sistema. Esto afecta a los clústeres de modo de cumplimiento. | |
| Modificada | Alta (7.5) | 0.91% | — | Protocol Go-unixfsnode | 9/2/2023 | 17/6/2026 | github.com/ipfs/go-unixfsnode es un nodo principal de ADL IPLD que envuelve la implementación de protobuf de go-codec-dagpb para habilitar la ruta. En versiones anteriores a la 1.5.2, intentar leer directorios fragmentados con HAMT con formato incorrecto puede provocar pánico y pérdidas de memoria virtual. Si está… | |
| Modificada | Alta (7.5) | 0.68% | — | Protocol Go-unixfs | 9/2/2023 | 17/6/2026 | go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus `fanout` parameter in the HAMT… | |
| Modificada | Alta (7.8) | 0.34% | — | WFS Another Eden | 6/2/2023 | 17/6/2026 | The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege escalation via a crafted payload. | |
| Modificada | Alta (8.8) | 0.63% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges. | |
| Modificada | Alta (8.1) | 0.66% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service. | |
| Modificada | Media (5.5) | 0.17% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover. | |
| Modificada | Alta (7.5) | 0.77% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.8) | 0.51% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise | |
| Modificada | Media (5.5) | 0.12% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Crítica (9.8) | 0.82% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution. | |
| Modificada | Alta (8.8) | 0.41% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure. | |
| Modificada | Media (6.5) | 0.49% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information. | |
| Modificada | Media (6.7) | 0.64% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and… | |
| Modificada | Media (5.5) | 0.35% | — | Yaffshiv Project Yaffshiv | 31/1/2023 | 17/6/2026 | Una vulnerabilidad de path traversal afecta al extractor del sistema de archivos yaffshiv YAFFS. Al crear un archivo YAFFS malicioso, un atacante podría obligar a yaffshiv a escribir fuera del directorio de extracción. Este problema afecta a yaffshiv hasta la versión 0.1 incluida, que es la más reciente en el momento… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Múltiples productos locales de Zoho ManageEngine, como ServiceDesk Plus hasta 14003, permiten la ejecución remota de código debido al uso de Apache Santuario xmlsec (también conocido como XML Security para Java) 1.4.1, porque las funciones xmlsec XSLT, por diseño en esa versión, hacen la aplicación responsable de… | |
| Modificada | Alta (7.8) | 0.70% | — | Qualcomm Apq8064au FirmwareQualcomm Apq8096au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+143 | 9/1/2023 | 17/6/2026 | Corrupción de la memoria debido al desbordamiento de búfer en la región stack de la memoria en Core | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 Firmware+189 | 9/1/2023 | 17/6/2026 | Divulgación de información debido a sobrelectura del búfer en Core | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+156 | 9/1/2023 | 17/6/2026 | Divulgación de información debido a sobrelectura del búfer en Core |