Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 6/7/2020 | 17/6/2026 | Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage of insufficiently applied file permissions or gain unauthorized access to files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Powerschool Mobile | 15/10/2019 | 17/6/2026 | In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat. | |
| Modificada | Alta (8.1) | 0.47% | — | Schneider-electric Powerscada Anywhere | 12/2/2018 | 17/6/2026 | A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social… | |
| Modificada | Media (5.5) | 0.46% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes. | |
| Modificada | Media (6.5) | 0.78% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate. | |
| Modificada | Media (6.5) | 0.56% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components. | |
| Modificada | Alta (8.8) | 0.63% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social… | |
| Modificada | Media (5.9) | 1.6% | — | Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareSamsung X14j FirmwareZyxel Gs1900-10hp Firmware+1 | 6/4/2016 | 17/6/2026 | The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673. | |
| Modificada | Alta (7.5) | 1.9% | — | Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware | 6/4/2016 | 17/6/2026 | Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348. | |
| Modificada | Alta (7.8) | 1.8% | — | Schneider-electric CitectscadaSchneider-electric Powerlogic ScadaSchneider-electric Struxureware Powerscada ExpertSchneider-electric Struxureware Scada Expert Vijeo Citect | 26/2/2014 | 16/6/2026 | Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Powerscripts Powerclan | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 0.96% | 💥 Exploit | Powerscripts Powernews | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Powerscripts Powerphpboard | 28/3/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Powerscripts Powerbook | 28/3/2008 | 16/6/2026 | Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Powerscripts Powernews | 13/2/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Pearson Education Powerschool | 21/2/2007 | 16/6/2026 | Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2. | |
| Modificada | Media (5.1) | 3.0% | 💥 Exploit | Powerscripts Powerclan | 23/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Powerscripts Powerclan | 18/4/2006 | 16/6/2026 | SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Powerscripts.org Powerdownload | 1/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Powerscripts Plusmail | 11/1/2000 | 16/6/2026 | PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. |