Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.39%—Netapp Storagegrid19/9/202517/6/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node.
AnalizadaAlta (7.5)0.34%—Netapp Storagegrid19/9/202517/6/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager…
AnalizadaMedia (6.4)0.24%—Netapp Storagegrid19/9/202517/6/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific…
AnalizadaCrítica (9.8)0.37%—IBM Storage FusionIBM Storage Fusion HCIIBM Storage Fusion HCI FOR Watsonx11/9/202517/6/2026
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.
AplazadaMedia (4.9)0.50%—Keycloak-model-storage-serviceAI21/8/202517/6/2026
A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An…
AnalizadaAlta (8.8)0.30%—IBM Storage Virtualize18/8/202517/6/2026
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
AnalizadaMedia (5.4)0.18%—IBM Storage Ts4500 Library FirmwareIBM Diamondback Tape Library Firmware15/8/202517/6/2026
IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AplazadaMedia (5.4)0.12%—Intel Rapid Storage TechnologyAI12/8/202517/6/2026
Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.5)0.12%—Dell Elastic Cloud StorageDell Objectscale4/8/202517/6/2026
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (5.5)0.13%—Dell Elastic Cloud StorageDell Objectscale15/7/202517/6/2026
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaMedia (6.5)0.29%—IBM Storage Scale12/7/202517/6/2026
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol.
AnalizadaAlta (7)0.09%—IBM Storage Virtualize7/7/202517/6/2026
IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.
AplazadaMedia (5.1)0.22%—Purestorage FlasharrayAI16/6/202517/6/2026
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
AplazadaAlta (8.3)0.33%—Purestorage FlashbladeAI10/6/202517/6/2026
Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.
AplazadaAlta (8.7)0.38%—Purestorage FlasharrayAI10/6/202517/6/2026
Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.
AplazadaMedia (4.3)0.28%—6storage RentalsAI6/6/202517/6/2026
Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.19.5.
AplazadaMedia (6.5)0.38%—6storage RentalsAI23/5/202517/6/2026
Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a through <= 2.20.2.
AplazadaMedia (4.7)0.21%—Ecovacs HomeAIAlibaba Object Storage ServiceAI23/5/202517/6/2026
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.
ModificadaAlta (8.8)0.43%—IBM Storage Scale10/5/202517/6/2026
IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.
ModificadaCrítica (9.8)3.5%💥 PoCMicrosoft Azure Storage Resource Provider8/5/202517/6/2026
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8)0.56%—Dell Storage Manager6/5/202517/6/2026
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (5.2)0.26%—Dell Storage Manager6/5/202517/6/2026
Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
AnalizadaMedia (4.3)0.28%—Dell Storage Manager6/5/202517/6/2026
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
AnalizadaAlta (8.1)0.29%—Dell Storage Manager6/5/202517/6/2026
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
AnalizadaAlta (8.8)0.31%—Dell Storage Manager6/5/202517/6/2026
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges.