Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.39% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node. | |
| Analizada | Alta (7.5) | 0.34% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager… | |
| Analizada | Media (6.4) | 0.24% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific… | |
| Analizada | Crítica (9.8) | 0.37% | — | IBM Storage FusionIBM Storage Fusion HCIIBM Storage Fusion HCI FOR Watsonx | 11/9/2025 | 17/6/2026 | IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions. | |
| Aplazada | Media (4.9) | 0.50% | — | Keycloak-model-storage-serviceAI | 21/8/2025 | 17/6/2026 | A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An… | |
| Analizada | Alta (8.8) | 0.30% | — | IBM Storage Virtualize | 18/8/2025 | 17/6/2026 | IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Storage Ts4500 Library FirmwareIBM Diamondback Tape Library Firmware | 15/8/2025 | 17/6/2026 | IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Rapid Storage TechnologyAI | 12/8/2025 | 17/6/2026 | Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Elastic Cloud StorageDell Objectscale | 4/8/2025 | 17/6/2026 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.5) | 0.13% | — | Dell Elastic Cloud StorageDell Objectscale | 15/7/2025 | 17/6/2026 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.5) | 0.29% | — | IBM Storage Scale | 12/7/2025 | 17/6/2026 | IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol. | |
| Analizada | Alta (7) | 0.09% | — | IBM Storage Virtualize | 7/7/2025 | 17/6/2026 | IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function. | |
| Aplazada | Media (5.1) | 0.22% | — | Purestorage FlasharrayAI | 16/6/2025 | 17/6/2026 | A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured. | |
| Aplazada | Alta (8.3) | 0.33% | — | Purestorage FlashbladeAI | 10/6/2025 | 17/6/2026 | Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service. | |
| Aplazada | Alta (8.7) | 0.38% | — | Purestorage FlasharrayAI | 10/6/2025 | 17/6/2026 | Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service. | |
| Aplazada | Media (4.3) | 0.28% | — | 6storage RentalsAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.19.5. | |
| Aplazada | Media (6.5) | 0.38% | — | 6storage RentalsAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a through <= 2.20.2. | |
| Aplazada | Media (4.7) | 0.21% | — | Ecovacs HomeAIAlibaba Object Storage ServiceAI | 23/5/2025 | 17/6/2026 | Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure. | |
| Modificada | Alta (8.8) | 0.43% | — | IBM Storage Scale | 10/5/2025 | 17/6/2026 | IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization. | |
| Modificada | Crítica (9.8) | 3.5% | 💥 PoC | Microsoft Azure Storage Resource Provider | 8/5/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8) | 0.56% | — | Dell Storage Manager | 6/5/2025 | 17/6/2026 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (5.2) | 0.26% | — | Dell Storage Manager | 6/5/2025 | 17/6/2026 | Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Media (4.3) | 0.28% | — | Dell Storage Manager | 6/5/2025 | 17/6/2026 | Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (8.1) | 0.29% | — | Dell Storage Manager | 6/5/2025 | 17/6/2026 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Analizada | Alta (8.8) | 0.31% | — | Dell Storage Manager | 6/5/2025 | 17/6/2026 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges. |