Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.33% | — | IBM Storage Scale | 14/12/2024 | 17/6/2026 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Storage Scale | 14/12/2024 | 17/6/2026 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system. | |
| Analizada | Media (4.3) | 0.32% | — | Dell Elastic Cloud Storage | 9/12/2024 | 17/6/2026 | Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage. | |
| Analizada | Media (4.3) | 0.36% | — | Netapp Storagegrid | 8/11/2024 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash. | |
| Analizada | Media (5.3) | 0.30% | — | Iowacomputergurus Aspnetcore.utilities.cloudstorage | 30/10/2024 | 17/6/2026 | ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not… | |
| Analizada | Media (5.9) | 1.0% | 💥 PoC | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 27/10/2024 | 17/6/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Purestorage FlasharrayAI | 8/10/2024 | 17/6/2026 | A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. | |
| Analizada | Media (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 3/10/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… | |
| Analizada | Media (6.5) | 0.34% | — | IBM Storage Defender | 25/9/2024 | 17/6/2026 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. | |
| Analizada | Alta (8.8) | 0.63% | — | Purestorage Purity//faPurestorage Purity//fb | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration. | |
| Analizada | Alta (7.2) | 0.64% | — | Purestorage Purity//fa | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array. | |
| Analizada | Alta (7.2) | 0.47% | — | Purestorage Purity//fa | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access. | |
| Analizada | Crítica (9.8) | 0.60% | — | Purestorage Purity//fa | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array. | |
| Analizada | Crítica (9.8) | 0.95% | — | Purestorage Purity//fa | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges. | |
| Analizada | Media (6.5) | 0.15% | — | Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+27 | 29/8/2024 | 17/6/2026 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6) | 0.14% | — | Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+27 | 29/8/2024 | 17/6/2026 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (4.3) | 0.13% | — | Intel Memory AND Storage Tool GUI | 14/8/2024 | 17/6/2026 | Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (6.5) | 0.33% | — | Dell Elastic Cloud Storage | 18/7/2024 | 17/6/2026 | Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Purestorage FlashbladeAI | 17/7/2024 | 17/6/2026 | A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array. | |
| Analizada | Media (4.7) | 0.38% | — | Oracle ZFS Storage Appliance KIT | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks… | |
| Analizada | Alta (7.4) | 1.1% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Modificada | Media (4.8) | 0.86% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+4 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Media (4.8) | 0.94% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… |