Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
5093 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.30% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel. | |
| Analizada | Media (4.3) | 0.20% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel. | |
| Analizada | Crítica (9.8) | 0.68% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 22/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access… | |
| Aplazada | Media (6.3) | 0.51% | — | Data Sharing FrameworkAI | 21/4/2026 | 17/6/2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request… | |
| Aplazada | Media (6.8) | 0.22% | — | Data Sharing FrameworkAI | 21/4/2026 | 17/6/2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is… | |
| Analizada | Baja (2.4) | 0.27% | — | Oracle Database Server | 21/4/2026 | 17/6/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Access Method privilege with network access via multiple protocols to compromise RDBMS. Successful attacks require human… | |
| Analizada | Media (5.3) | 0.24% | — | Oracle XML Database | 21/4/2026 | 8/7/2026 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction from a person other… | |
| Aplazada | Media (4.7) | 0.24% | — | WpdatatablesAI | 20/4/2026 | 17/6/2026 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn,… | |
| Modificada | Media (6.7) | 0.13% | — | Dell Data Domain Operating System | 20/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability. A high privileged attacker with local access could… | |
| Analizada | Media (6.7) | 0.19% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 1.4% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root… | |
| Analizada | Alta (7.2) | 1.2% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 0.42% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (7.2) | 0.44% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Analizada | Alta (7.2) | 1.2% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (8.8) | 0.77% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this… | |
| Analizada | Alta (7.2) | 1.5% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 20/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker with remote access… | |
| Modificada | Crítica (9.4) | 2.1% | 💥 PoC | Asustor Data Master | 20/4/2026 | 17/6/2026 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is… | |
| Analizada | Alta (8.6) | 0.76% | 💥 PoC | Asustor Data Master | 20/4/2026 | 17/6/2026 | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to execute arbitrary… | |
| Analizada | Media (4.8) | 0.24% | — | Dell Powerprotect Data DomainDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker with remote access… | |
| Analizada | Media (6.5) | 0.30% | — | Dell Powerprotect Data DomainDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an exposure of sensitive information to an unauthorized actor vulnerability. A low… | |
| Modificada | Media (6.7) | 0.25% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A… | |
| Modificada | Media (6.7) | 0.62% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high… | |
| Modificada | Media (6.7) | 0.62% | — | Dell Data Domain Operating System | 17/4/2026 | 4/8/2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high… |