Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

2343 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1519/8/202626/8/2026
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to…
Pendiente de análisisMedia (5.3)0.12%—Dell PowerpathAI19/8/202620/8/2026
Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
En análisisMedia (6)0.10%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1519/8/202625/8/2026
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.
Pendiente de análisisAlta (8.1)0.40%—Dell PowerstoreAI18/8/202620/8/2026
Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.
Pendiente de análisisAlta (7.3)0.17%—Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+518/8/202620/8/2026
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4…
Pendiente de análisisAlta (8.1)0.61%—Dell Powerstore SdnasAI18/8/202631/8/2026
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.
Pendiente de análisisCrítica (9.8)0.83%—Dell Powerstore SdnasAI18/8/202631/8/2026
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet…
AplazadaMedia (4.8)0.17%—Powerlevel10kAI17/8/202624/9/2026
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.
AnalizadaAlta (7.8)0.32%—Microsoft Powershell14/8/202618/8/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Pendiente de análisisAlta (8.1)0.39%—Devolutions Powershell UniversalAI14/8/202628/8/2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the…
AnalizadaMedia (4.2)0.16%—IBM Datapower Gateway12/8/20264/10/2026
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing,…
AplazadaAlta (7.1)0.29%—Blubrry PowerpressAI12/8/202626/8/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
AnalizadaAlta (7.8)0.36%—Microsoft Powershell11/8/202614/8/2026
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.94%—Microsoft Powershell11/8/202614/8/2026
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.8)0.96%—Microsoft Power BI Report Server11/8/202619/8/2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.3)0.38%—Microsoft Powershell11/8/202617/8/2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.87%—Microsoft Powershell11/8/202617/8/2026
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisAlta (7)0.16%—AMD Power Design ManagerAI11/8/202629/9/2026
A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.
AplazadaAlta (7.1)0.16%—Powersoftware PowerisoAI7/8/202612/8/2026
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The…
ModificadaCrítica (9.3)0.72%—Microsoft Power Apps7/8/202611/8/2026
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (6.5)0.22%—Codesupplyco PowerkitAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
AplazadaMedia (6.8)0.43%—Blubrry PowerpressAI4/8/202626/8/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
AplazadaMedia (6.4)0.35%—Codesupplyco PowerkitAI1/8/202612/8/2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (6.4)0.36%—Codesupplyco PowerkitAI1/8/202612/8/2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…