Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

703 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)77%⚠ Explotación activa💥 ExploitProgress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster4/6/20261/10/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Pendiente de análisisAlta (8.8)0.44%—Infoscale CmdserverAI20/5/202623/7/2026
InfoScale CmdServer before 7.4.2 mishandles access control.
AnalizadaAlta (8.8)0.22%—Veritas Infoscale Operations Manager20/5/202623/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.
AnalizadaMedia (5.4)0.24%—Veritas Infoscale Operations Manager20/5/202623/7/2026
InfoScale VIOM 9.1.3 allows XSS.
AnalizadaMedia (6.5)0.35%—Veritas Infoscale Operations Manager20/5/202623/7/2026
SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
AnalizadaAlta (7.8)0.30%—Dell Elastic Cloud StorageDell Objectscale11/5/202617/6/2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.
AnalizadaCrítica (9.8)0.45%—Dell Elastic Cloud StorageDell Objectscale11/5/202617/6/2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
AnalizadaMedia (6.7)0.15%—Dell Elastic Cloud StorageDell Objectscale11/5/202617/6/2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in the OS. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AnalizadaMedia (5.6)0.24%—Dell Elastic Cloud StorageDell Objectscale11/5/202617/6/2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in…
AnalizadaAlta (8.9)0.70%—Anyscale RAY8/5/202617/6/2026
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When PyArrow reads a Parquet file containing one of these extension types, it calls…
AnalizadaBaja (3.3)0.13%—Dell Powerscale Onefs8/5/202617/6/2026
Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Pendiente de análisisCrítica (9.8)0.84%—Crowdstrike LogscaleAI21/4/202617/6/2026
CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific…
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
AnalizadaMedia (6.6)0.14%—Dell Powerscale Onefs16/4/20267/10/2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed…
AnalizadaMedia (4.4)0.14%—Dell Powerscale Onefs16/4/20267/10/2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (4.1)0.14%—Dell Powerscale Onefs16/4/20267/10/2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (5.5)0.15%—Dell Elastic Cloud StorageDell Objectscale8/4/202624/7/2026
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure.…
AnalizadaAlta (7.8)0.13%—Dell Powerscale Onefs8/4/202624/7/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
AnalizadaMedia (4.4)0.16%—Dell Powerscale Onefs8/4/202624/7/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
AnalizadaMedia (5.3)0.18%—Zscaler Client Connector31/3/202624/7/2026
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
Pendiente de análisisAlta (7.7)0.29%—Citrix Netscaler ADCAICitrix Netscaler GatewayAI23/3/202617/6/2026
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
AnalizadaCrítica (9.3)4.0%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway23/3/202617/6/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Orbitaley — Vulnerabilidades