Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.25% | — | IBM Storage Protect Server | 1/4/2026 | 17/6/2026 | IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Baja (2.1) | 0.20% | — | Nhost Storage | 20/3/2026 | 17/6/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an attacker to upload files with an arbitrary MIME type, bypassing any… | |
| Aplazada | Alta (8.7) | 0.43% | — | Craftcms Azure Blob StorageAICraftcms Craft CMSAI | 18/3/2026 | 17/6/2026 | The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a… | |
| Aplazada | Baja (2.4) | 0.46% | — | Google Cloud StorageAICraftcms Craft CMSAICraftcms Google Cloud StorageAI | 18/3/2026 | 17/6/2026 | The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to… | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Storage Scale | 3/3/2026 | 17/6/2026 | IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be executed by unintended actors. | |
| Modificada | Alta (7.6) | 0.43% | — | Keystorage Global Facilities Management Software | 20/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and gn parameters on the /?Function=Groups endpoint. | |
| Analizada | Alta (8.2) | 0.49% | — | Keystorage Global Facilities Management Software | 20/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter. | |
| Analizada | Crítica (9.4) | 0.53% | — | Keystorage Global Facilities Management Software | 20/2/2026 | 17/6/2026 | An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality. | |
| Analizada | Alta (7.1) | 0.41% | — | Keystorage Global Facilities Management Software | 20/2/2026 | 17/6/2026 | An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter. | |
| Aplazada | Alta (7.1) | 0.29% | — | Netapp StoragegridAI | 18/2/2026 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Memory AND Storage ToolAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially… | |
| Aplazada | Crítica (9.1) | 0.29% | — | Google Cloud StorageAIGoogle Cloud SQLAI | 6/2/2026 | 17/6/2026 | The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in… | |
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Aplazada | Alta (7.1) | 0.21% | — | Crucial Storage ExecutiveAI | 26/1/2026 | 17/6/2026 | Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of… | |
| Analizada | Media (5.5) | 0.10% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (4.4) | 0.14% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.18% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with remote access could potentially exploit this vulnerability to intercept and modify information in… | |
| Analizada | Alta (8.8) | 0.37% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.5) | 0.22% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | |
| Analizada | Baja (2.3) | 0.15% | — | Oracle SUN ZFS Storage Appliance KIT | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle… | |
| Aplazada | Media (5.4) | 0.19% | — | 6storage RentalsAI | 24/12/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.22.0. | |
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 7/10/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Aplazada | Media (5.8) | 0.39% | — | Kubernetes Kube-controller-managerAIPurestorage PortworxAI | 14/12/2025 | 17/6/2026 | A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback… | |
| Analizada | Media (6.5) | 0.27% | — | IBM Storage Defender Resiliency Service | 8/12/2025 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. | |
| Analizada | Alta (8.4) | 0.13% | — | Purestorage Portworx | 4/12/2025 | 17/6/2026 | A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions. |