Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
2384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.18% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.9) | 0.18% | — | IBM Powervm Hypervisor | 23/5/2023 | 17/6/2026 | IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer… | |
| Modificada | Crítica (9.8) | 0.38% | — | Schneider-electric Powerlogic Ion9000 FirmwareSchneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Pm8000 FirmwareSchneider-electric Powerlogic Ion8650 Firmware+1 | 22/5/2023 | 17/6/2026 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Poweredge R740 FirmwareDell Poweredge R740xd FirmwareDell Poweredge R640 FirmwareDell Poweredge R940 Firmware+26 | 22/5/2023 | 17/6/2026 | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading… | |
| Modificada | Alta (8.8) | 0.24% | — | IBM Powervm Hypervisor | 17/5/2023 | 17/6/2026 | An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other… | |
| Modificada | Alta (7.2) | 0.70% | — | Apsystems Alternergy Power Control Software | 11/5/2023 | 17/6/2026 | Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php. | |
| Modificada | Alta (7.5) | 0.64% | — | SAP Powerdesigner Proxy | 9/5/2023 | 17/6/2026 | In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application. | |
| Modificada | Alta (7.5) | 2.8% | — | Gavazzionline Powersoft | 4/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Crítica (9.8) | 1.0% | — | Cyberpower Powerpanel | 24/4/2023 | 17/6/2026 | Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6… | |
| Modificada | Crítica (9.8) | 1.1% | — | Cyberpower Powerpanel | 24/4/2023 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for… | |
| Modificada | Crítica (9.8) | 0.97% | — | Cyberpower Powerpanel | 24/4/2023 | 17/6/2026 | Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel… | |
| Modificada | Crítica (9.8) | 1.1% | — | Powerjob | 21/4/2023 | 17/6/2026 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution. | |
| Modificada | Crítica (9.8) | 1.2% | — | Powerjob | 20/4/2023 | 17/6/2026 | PowerJob V4.3.2 has unauthorized interface that causes remote code execution. | |
| Modificada | Media (5.3) | 3.0% | 💥 Exploit | Powerjob | 19/4/2023 | 17/6/2026 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. | |
| Modificada | Media (5.3) | 9.5% | 💥 Exploit | Powerjob | 19/4/2023 | 17/6/2026 | PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface. | |
| Modificada | Media (5.3) | 0.53% | — | Powerjob | 19/4/2023 | 17/6/2026 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface. | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric Powerlogic Hdpm6000 Firmware | 18/4/2023 | 17/6/2026 | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution. | |
| Modificada | Alta (8.8) | 0.32% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 18/4/2023 | 17/6/2026 | A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account. | |
| Modificada | Alta (7.5) | 1.5% | — | Powerampapp Poweramp | 14/4/2023 | 17/6/2026 | An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library | |
| Modificada | Alta (8.8) | 0.77% | — | Dell Powerprotect Data Manager | 11/4/2023 | 17/6/2026 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions. | |
| Modificada | Crítica (9.8) | 1.5% | — | Powerampapp Poweramp | 11/4/2023 | 17/6/2026 | An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Power Manager | 7/4/2023 | 17/6/2026 | Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system. | |
| Modificada | Media (5.3) | 0.59% | — | Powerdns Recursor | 4/4/2023 | 17/6/2026 | Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3. |