Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.36% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (8.8) | 0.63% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system. | |
| Analizada | Crítica (9.8) | 0.56% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the… | |
| Analizada | Media (6.5) | 0.38% | — | IBM Guardium Data Protection | 27/5/2026 | 17/6/2026 | IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode. | |
| Analizada | Media (4.8) | 0.24% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.8) | 0.24% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.9) | 0.42% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |
| Analizada | Media (4.9) | 0.30% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel. | |
| Analizada | Media (4.3) | 0.20% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel. | |
| Analizada | Media (6.5) | 0.32% | — | Dell Data Protection Advisor | 23/1/2026 | 17/6/2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.5) | 0.21% | — | IBM Guardium Data Protection | 6/8/2025 | 17/6/2026 | IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Guardium Data Protection | 11/6/2025 | 17/6/2026 | IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program. | |
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.1) | 0.20% | — | General Data Protection Regulation Project General Data Protection Regulation | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2. | |
| Analizada | Media (6.5) | 0.13% | — | Dell Data Protection AdvisorDell Dp4400 FirmwareDell Dp5900 Firmware | 29/5/2024 | 17/6/2026 | Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Modificada | Crítica (9.8) | 0.64% | — | Dell Data Protection Search | 6/2/2024 | 17/6/2026 | Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote… | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.2) | 1.8% | — | Dell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management CenterDell EMC Data Domain OS+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying… | |
| Modificada | Media (6.1) | 0.76% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM… | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege. | |
| Modificada | Media (4.3) | 0.57% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized… | |
| Modificada | Media (6.7) | 0.62% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by… | |
| Modificada | Media (6.7) | 0.29% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the… | |
| Modificada | Alta (7.8) | 0.60% | — | Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+1 | 14/12/2023 | 17/6/2026 | Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |