Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa💥 Exploit | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | Infoscale CmdserverAI | 20/5/2026 | 23/7/2026 | InfoScale CmdServer before 7.4.2 mishandles access control. | |
| Analizada | Alta (8.8) | 0.22% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge. | |
| Analizada | Media (5.4) | 0.24% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | InfoScale VIOM 9.1.3 allows XSS. | |
| Analizada | Media (6.5) | 0.35% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | |
| Analizada | Alta (7.8) | 0.30% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.45% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in the OS. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (5.6) | 0.24% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in… | |
| Analizada | Alta (8.9) | 0.70% | — | Anyscale RAY | 8/5/2026 | 17/6/2026 | Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When PyArrow reads a Parquet file containing one of these extension types, it calls… | |
| Analizada | Baja (3.3) | 0.13% | — | Dell Powerscale Onefs | 8/5/2026 | 17/6/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Crítica (9.8) | 0.84% | — | Crowdstrike LogscaleAI | 21/4/2026 | 17/6/2026 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific… | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command | |
| Analizada | Media (6.6) | 0.14% | — | Dell Powerscale Onefs | 16/4/2026 | 7/10/2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Analizada | Media (4.4) | 0.14% | — | Dell Powerscale Onefs | 16/4/2026 | 7/10/2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (4.1) | 0.14% | — | Dell Powerscale Onefs | 16/4/2026 | 7/10/2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 8/4/2026 | 24/7/2026 | Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure.… | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Powerscale Onefs | 8/4/2026 | 24/7/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (4.4) | 0.16% | — | Dell Powerscale Onefs | 8/4/2026 | 24/7/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (5.3) | 0.18% | — | Zscaler Client Connector | 31/3/2026 | 24/7/2026 | An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances. | |
| Pendiente de análisis | Alta (7.7) | 0.29% | — | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 23/3/2026 | 17/6/2026 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | |
| Analizada | Crítica (9.3) | 4.0% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 23/3/2026 | 17/6/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread |