Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
2385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.18% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. | |
| Modificada | Alta (8.8) | 0.31% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user. | |
| Modificada | Alta (8.1) | 0.79% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Powerscale Onefs | 11/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (7.5) | 0.43% | — | Dell Powerscale Onefs | 11/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak. | |
| Modificada | Media (4.8) | 0.39% | — | Dell EMC Powerscale Onefs | 10/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields. | |
| Modificada | Media (6.7) | 0.19% | — | Dell EMC Powerscale Onefs | 10/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versiones 8.2.x-9.3.x, contiene un desbordamiento de búfer basado en almacenamiento dinámico. Un usuario local malicioso con privilegios podría explotar esta vulnerabilidad y tomar el control del sistema. Esto afecta a los clústeres de modo de cumplimiento. | |
| Modificada | Baja (2.7) | 0.43% | — | Dell Powerpath Management Appliance | 10/2/2023 | 17/6/2026 | PowerPath Management Appliance con versiones 3.3, 3.2*, 3.1 y 3.1. 3.0* contiene una vulnerabilidad de divulgación de información confidencial. Un usuario administrador autenticado puede aprovechar el problema y ver información confidencial almacenada en los registros. | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Alta (8.8) | 0.63% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges. | |
| Modificada | Alta (8.1) | 0.66% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service. | |
| Modificada | Media (5.5) | 0.17% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover. | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.5) | 0.77% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.8) | 0.51% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise | |
| Modificada | Media (5.5) | 0.12% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Crítica (9.8) | 0.82% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution. | |
| Modificada | Alta (8.8) | 0.41% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure. | |
| Modificada | Media (6.5) | 0.49% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information. | |
| Modificada | Media (6.7) | 0.64% | — | Dell EMC Powerscale Onefs | 1/2/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and… |