Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.07%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AnalizadaMedia (5.5)0.10%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.
AnalizadaAlta (7.5)0.13%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaAlta (7.8)0.09%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (5.5)0.10%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.
AnalizadaMedia (6.5)0.08%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.
AnalizadaMedia (6.5)0.77%—Powerdns Authoritative21/5/202623/7/2026
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
AnalizadaAlta (7.5)0.58%—Powerdns Authoritative21/5/202623/7/2026
Concurrency and locking defects in GSS-TSIG
AnalizadaAlta (7.5)0.80%—Powerdns Authoritative21/5/202623/7/2026
Insufficient Validation of Autoprimary SOA Queries
AnalizadaAlta (8.6)0.54%—Powerdns Authoritative21/5/202623/7/2026
Insufficient Validation of Names During AXFR
AnalizadaMedia (4.8)0.19%—Powerdns Authoritative21/5/202623/7/2026
Incorrect Behaviour of Views with TCP PROXY Requests
AnalizadaAlta (7.5)0.35%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack20/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
ModificadaAlta (7.5)1.1%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+1018/5/20262/10/2026
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable…
Pendiente de análisisMedia (6.8)0.11%—AMD Power Management FirmwareAI15/5/202617/6/2026
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability.
Pendiente de análisisAlta (7)0.22%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
Pendiente de análisisMedia (6.9)0.22%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
Pendiente de análisisAlta (8.4)0.21%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
Pendiente de análisisMedia (5.1)0.31%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
AnalizadaMedia (5.5)0.31%—Microsoft Powerpoint12/5/202617/6/2026
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
AnalizadaMedia (6.5)1.00%—Microsoft Power Automate FOR Desktop12/5/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
AnalizadaBaja (3.3)0.13%—Dell Powerscale Onefs8/5/202617/6/2026
Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
AplazadaBaja (2.1)0.38%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit…
AplazadaMedia (5.5)0.41%—Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The…
AplazadaMedia (6.8)0.13%—Drive Power ManagerAI26/4/202617/6/2026
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition.
AnalizadaAlta (8)0.57%—Microsoft Power Apps23/4/202617/6/2026
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.