Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

703 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.12%—Dell Elastic Cloud StorageDell Objectscale4/8/202517/6/2026
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (4.9)0.21%—Dell Powerscale Onefs21/7/202517/6/2026
Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaMedia (5.5)0.13%—Dell Elastic Cloud StorageDell Objectscale15/7/202517/6/2026
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaMedia (6.5)0.29%—IBM Storage Scale12/7/202517/6/2026
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol.
AplazadaAlta (7.1)0.21%—Nokia Single RAN Airscale BasebandAI2/7/202517/6/2026
Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards using the internal…
AnalizadaCrítica (9.2)11%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway25/6/202517/6/2026
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AnalizadaAlta (7.8)0.19%—Dell Powerscale Onefs20/6/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and…
AnalizadaCrítica (9.8)0.50%—Dell Powerscale Onefs20/6/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify, and delete…
AnalizadaAlta (8.7)6.2%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/202517/6/2026
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
AnalizadaMedia (6.9)11%—Citrix Netscaler ConsoleCitrix Netscaler SDX17/6/202517/6/2026
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
ModificadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/20257/10/2026
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AplazadaAlta (7.3)0.10%—Zscaler Client ConnectorAI4/6/202517/6/2026
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
AnalizadaAlta (7.5)0.48%—Dell Powerscale Onefs15/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.
ModificadaAlta (8.8)0.43%—IBM Storage Scale10/5/202517/6/2026
IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.
AnalizadaMedia (5.5)0.22%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6.3)0.16%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.
AplazadaAlta (7.2)0.29%—Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI25/4/202517/6/2026
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
AplazadaCrítica (9.9)0.74%—Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI25/4/202517/6/2026
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
AnalizadaMedia (6.5)0.13%—Dell Elastic Cloud StorageDell Objectscale17/4/202517/6/2026
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (8.8)0.42%—Dell Elastic Cloud StorageDell Objectscale17/4/202517/6/2026
Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaCrítica (9.8)0.47%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.
AnalizadaAlta (7.5)0.45%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
AnalizadaBaja (3.1)0.25%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.
AnalizadaAlta (7)0.15%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
AnalizadaBaja (3.3)0.16%—Dell Powerscale Onefs10/4/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Orbitaley — Vulnerabilidades