Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+15 | 19/8/2026 | 26/8/2026 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to… | |
| Pendiente de análisis | Media (5.3) | 0.12% | — | Dell PowerpathAI | 19/8/2026 | 20/8/2026 | Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Media (6) | 0.10% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+15 | 19/8/2026 | 25/8/2026 | IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings. | |
| Pendiente de análisis | Alta (8.1) | 0.40% | — | Dell PowerstoreAI | 18/8/2026 | 20/8/2026 | Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Pendiente de análisis | Alta (8.1) | 0.61% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service. | |
| Pendiente de análisis | Crítica (9.8) | 0.83% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet… | |
| Aplazada | Media (4.8) | 0.17% | — | Powerlevel10kAI | 17/8/2026 | 24/9/2026 | powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Powershell | 14/8/2026 | 18/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Devolutions Powershell UniversalAI | 14/8/2026 | 28/8/2026 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the… | |
| Analizada | Media (4.2) | 0.16% | — | IBM Datapower Gateway | 12/8/2026 | 4/10/2026 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing,… | |
| Aplazada | Alta (7.1) | 0.29% | — | Blubrry PowerpressAI | 12/8/2026 | 26/8/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Powershell | 11/8/2026 | 14/8/2026 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Powershell | 11/8/2026 | 14/8/2026 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 11/8/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.3) | 0.38% | — | Microsoft Powershell | 11/8/2026 | 17/8/2026 | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.87% | — | Microsoft Powershell | 11/8/2026 | 17/8/2026 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Alta (7) | 0.16% | — | AMD Power Design ManagerAI | 11/8/2026 | 29/9/2026 | A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.1) | 0.16% | — | Powersoftware PowerisoAI | 7/8/2026 | 12/8/2026 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The… | |
| Modificada | Crítica (9.3) | 0.72% | — | Microsoft Power Apps | 7/8/2026 | 11/8/2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.5) | 0.22% | — | Codesupplyco PowerkitAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Blubrry PowerpressAI | 4/8/2026 | 26/8/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Aplazada | Media (6.4) | 0.35% | — | Codesupplyco PowerkitAI | 1/8/2026 | 12/8/2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.4) | 0.36% | — | Codesupplyco PowerkitAI | 1/8/2026 | 12/8/2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |