Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.27% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (8.8) | 0.31% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (8.7) | 0.24% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this… | |
| Aplazada | Alta (8.7) | 0.22% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An attacker can issue an api call to… | |
| Analizada | Media (6.5) | 0.14% | — | Evervault | 12/11/2025 | 17/6/2026 | Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that may allow incomplete documents to pass validation. This may cause the client to trust an enclave operator that does not meet expected… | |
| Analizada | Alta (7.5) | 0.53% | — | Hashicorp Vault | 23/10/2025 | 17/6/2026 | Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393] which allowed for… | |
| Analizada | Alta (8.1) | 0.49% | — | Hashicorp Vault | 23/10/2025 | 17/6/2026 | Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5,… | |
| Aplazada | Alta (7.7) | 0.32% | — | AliasvaultAI | 19/9/2025 | 17/6/2026 | AliasVault is a privacy-first password manager with built-in email aliasing. A server-side request forgery (SSRF) vulnerability exists in the favicon extraction feature of AliasVault API versions 0.23.0 and lower. The extractor fetches a user-supplied URL, parses the returned HTML, and follows <link rel="icon"… | |
| Aplazada | Alta (8.7) | 1.2% | — | Lemon8866 StreamvaultAI | 1/9/2025 | 17/6/2026 | StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker can modify certain system parameters, construct malicious commands, execute command injection attacks against the system, and ultimately gain server privileges. Users of… | |
| Analizada | Baja (1.9) | 0.22% | — | Galleryvault Gallery Vault | 30/8/2025 | 17/6/2026 | A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be… | |
| Analizada | Alta (7.5) | 0.70% | — | Hashicorp Vault | 28/8/2025 | 25/9/2026 | A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This… | |
| Modificada | Alta (7.8) | 0.19% | — | Openmediavault | 22/8/2025 | 5/7/2026 | An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root. | |
| Modificada | Media (6.9) | 25% | 💥 Exploit | Commvault | 20/8/2025 | 17/6/2026 | A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role. | |
| Modificada | Alta (8.7) | 19% | 💥 Exploit | Commvault | 20/8/2025 | 17/6/2026 | A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution. | |
| Modificada | Media (5.3) | 1.2% | 💥 Exploit | Commvault | 20/8/2025 | 17/6/2026 | During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured. | |
| Modificada | Media (6.9) | 2.9% | 💥 Exploit | Commvault | 20/8/2025 | 17/6/2026 | A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. | |
| Aplazada | Crítica (9.4) | 0.23% | — | VaultlsAI | 18/8/2025 | 17/6/2026 | VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This is combined with that fact, that previously disabling the password based login… | |
| Analizada | Alta (8.1) | 0.50% | — | Hashicorp Vault | 6/8/2025 | 17/6/2026 | Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24. | |
| Analizada | Baja (2) | 0.44% | — | Metaclinic Nanovault | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.8) | 0.25% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious… | |
| Analizada | Media (5.7) | 0.33% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23. |