Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.37% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Veritas InfoscaleAI | 7/3/2025 | 17/6/2026 | A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Plugin_Host service, which runs on all the servers where InfoScale is installed.… | |
| Aplazada | Alta (7.1) | 0.24% | — | Andrew Fisher WOO Codice FiscaleAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale woo-codice-fiscale allows Reflected XSS.This issue affects WOO Codice Fiscale: from n/a through <= 1.6.3. | |
| Aplazada | Media (5.1) | 0.35% | — | Pankajindevops ScaleAI | 22/2/2025 | 17/6/2026 | A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. The manipulation of the argument goal leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.45% | — | Theeventscalendar Event Tickets | 21/2/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (8.8) | 13% | — | Citrix Netscaler AgentCitrix Netscaler Console | 20/2/2025 | 17/6/2026 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | |
| Aplazada | Media (5.3) | 0.32% | — | Pankajindevops ScaleAI | 28/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why… | |
| Analizada | Media (5.4) | 0.29% | — | Theeventscalendar THE Events Calendar | 23/1/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.46% | — | Dell Powerscale Onefs | 8/1/2025 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerscale Onefs | 6/1/2025 | 17/6/2026 | Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Storage Scale | 14/12/2024 | 17/6/2026 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Storage Scale | 14/12/2024 | 17/6/2026 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system. | |
| Aplazada | Media (5.3) | 0.63% | — | Theeventscalendar THE Events CalendarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2. | |
| Analizada | Media (6.5) | 0.32% | — | Dell Powerscale Onefs | 9/12/2024 | 17/6/2026 | Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (6.5) | 0.37% | — | Dell Powerscale Onefs | 9/12/2024 | 17/6/2026 | Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (6.5) | 0.48% | — | Dell Powerscale Onefs | 9/12/2024 | 17/6/2026 | Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (4.8) | 0.29% | — | Hyscaler WP Roles AT Registration | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NetTantra WP Roles at Registration allows Stored XSS.This issue affects WP Roles at Registration: from n/a through 0.23. | |
| Analizada | Media (5.8) | 0.42% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA… | |
| Analizada | Alta (8.4) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway… | |
| Analizada | Alta (7.5) | 0.39% | — | Redhat 3scale API Management | 24/10/2024 | 17/6/2026 | A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a… | |
| Aplazada | Alta (7.7) | 0.36% | — | Atos Eviden SMC XscaleAI | 11/10/2024 | 17/6/2026 | An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to the security of the HPC configuration. Because these parameters… | |
| Modificada | Media (5.3) | 0.28% | — | Redhat 3scale API Management Platform | 9/10/2024 | 17/6/2026 | A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed. | |
| Aplazada | Media (5.1) | 0.66% | 💥 PoC | BPL Personal Weighing Scale Pws-01btAI | 3/9/2024 | 17/6/2026 | BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.) | |
| Analizada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 31/8/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access. | |
| Analizada | Media (6.3) | 0.19% | — | Dell Powerscale Onefs | 31/8/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering. |