Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.35% | — | Dell Elastic Cloud Storage | 22/5/2026 | 23/7/2026 | Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data. | |
| Analizada | Media (6.7) | 0.43% | — | Dell Smartfabric Storage Software | 20/5/2026 | 24/7/2026 | Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. | |
| Pendiente de análisis | Alta (8.7) | 0.84% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (7.8) | 0.30% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.45% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in the OS. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (5.6) | 0.24% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in… | |
| Analizada | Media (5.3) | 0.30% | — | Hitachi VSP E1090h FirmwareHitachi VSP E790h FirmwareHitachi VSP E590h FirmwareHitachi VSP E390h Firmware+16 | 7/5/2026 | 17/6/2026 | Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block… | |
| Analizada | Crítica (9.8) | 0.55% | — | Hitachi Virtual Storage ONE BlockHitachi VSP G130 FirmwareHitachi VSP G150 FirmwareHitachi VSP G350 Firmware+16 | 7/5/2026 | 17/6/2026 | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One… | |
| Analizada | Crítica (9.8) | 0.90% | — | Hitachi Virtual Storage ONE Block | 7/5/2026 | 17/6/2026 | OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. | |
| Analizada | Crítica (9.8) | 0.54% | — | IBM Total Storage Service ConsoleIBM Ts4500 IMC | 23/4/2026 | 17/6/2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Baja (2.3) | 0.18% | — | Netapp Storagegrid | 20/4/2026 | 8/7/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to. | |
| Pendiente de análisis | Alta (7.3) | 0.12% | — | Dell Storage Manager Replay Manager FOR Microsoft ServersAI | 16/4/2026 | 17/6/2026 | Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Media (6.9) | 0.38% | — | Purestorage Flasharray PurityAI | 14/4/2026 | 17/6/2026 | Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured. | |
| Pendiente de análisis | Alta (8.5) | 0.38% | — | Purestorage FlashbladeAI | 14/4/2026 | 17/6/2026 | A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. | |
| Aplazada | Baja (2.7) | 0.32% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 8/4/2026 | 24/7/2026 | Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure.… | |
| Analizada | Alta (8.8) | 3.4% | — | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |
| Analizada | Crítica (9.8) | 3.2% | 💥 Exploit | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. |