Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.15% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Modificada | Media (6.5) | 0.37% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Alta (8) | 0.25% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access. | |
| Modificada | Alta (7.1) | 0.32% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Alta (8.8) | 0.53% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information… | |
| Modificada | Alta (8.1) | 0.35% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Modificada | Alta (7.5) | 0.21% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.1) | 0.15% | — | Dell Powerflex Rack Release Certification Matrix | 17/6/2026 | 6/10/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections. | |
| Aplazada | Alta (8.8) | 0.50% | — | Powerpack PRO FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. | |
| Analizada | Media (6.5) | 0.12% | — | Dell Powerflex Manager | 17/6/2026 | 1/10/2026 | Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning. | |
| Modificada | Media (5.7) | 0.15% | — | Powerschool Employee Access Center | 16/6/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in… | |
| Pendiente de análisis | Media (5.4) | 0.20% | — | Dell PowerstoreAI | 16/6/2026 | 1/10/2026 | PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser. | |
| Aplazada | Alta (8.5) | 0.25% | — | Blubrry PowerpressAI | 15/6/2026 | 17/6/2026 | Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions. | |
| Analizada | Media (5.3) | 0.37% | — | Ironmansoftware Powershell Universal | 12/6/2026 | 17/6/2026 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints. | |
| Analizada | Alta (7.1) | 0.44% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft Word | 9/6/2026 | 23/7/2026 | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Powertoys | 9/6/2026 | 23/7/2026 | Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 1.5% | — | Microsoft Nuance Powerscribe 360Microsoft Nuance Powerscribe ONE | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7) | 0.17% | — | Draeger Zeus Infinity EmpoweredAIDraeger Zeus RS C500AIDraeger Service ConnectAI | 2/6/2026 | 22/7/2026 | Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy… | |
| Aplazada | Media (5.5) | 0.72% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 26/5/2026 | 23/7/2026 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud Platform 3000webv2AI | 26/5/2026 | 23/7/2026 | A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql… | |
| Analizada | Crítica (9.8) | 0.58% | — | Microsoft Power Pages | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.25% | — | Dell Unisphere FOR Powermax Virtual Appliance | 22/5/2026 | 23/7/2026 | Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing… |