Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.16% | — | Dell Powerscale Onefs | 15/7/2026 | 15/7/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Powerscale Onefs | 15/7/2026 | 16/7/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.4) | 0.52% | — | Microsoft Power BI Report Server | 14/7/2026 | 19/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.3) | 0.30% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.8) | 0.86% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (8.5) | 0.32% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and… | |
| Analizada | Alta (7.7) | 0.37% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Crítica (9.1) | 2.0% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary… | |
| Analizada | Media (6.5) | 0.45% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. | |
| Analizada | Media (6.5) | 0.44% | — | Devolutions Powershell Universal | 29/6/2026 | 2/7/2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses. | |
| Pendiente de análisis | Alta (8) | 1.3% | — | Dell Csi-powerstoreAIDell Csi-unityAIDell Csi-powerflexAIDell Csi-powermaxAI | 26/6/2026 | 26/6/2026 | Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially… | |
| Analizada | Media (6.9) | 0.43% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service. | |
| Analizada | Alta (8.6) | 1.7% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable… | |
| Analizada | Alta (8.7) | 0.46% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. | |
| Aplazada | Media (5.9) | 0.48% | — | Powerdns RecursorAI | 25/6/2026 | 25/6/2026 | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation. | |
| Aplazada | Baja (3.7) | 0.22% | — | Powerdns DnsdistAI | 25/6/2026 | 25/6/2026 | An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter. | |
| Aplazada | Crítica (9.6) | 0.54% | — | PoweradminAIPowerdnsAI | 23/6/2026 | 25/6/2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker… | |
| Aplazada | Media (6.9) | 0.38% | — | PoweradminAIPowerdnsAI | 23/6/2026 | 25/6/2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizing formula trigger… | |
| Aplazada | Media (6.4) | 0.20% | — | Blubrry PowerpressAI | 18/6/2026 | 18/6/2026 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Modificada | Alta (8) | 0.38% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection. | |
| Modificada | Media (5.7) | 0.30% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (8.1) | 0.34% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access. |