Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Dell EMC Isilon OnefsDell EMC Powerscale Onefs6/7/202017/6/2026
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage of insufficiently applied file permissions or gain unauthorized access to files.
ModificadaCrítica (9.8)1.2%—Powerschool Mobile15/10/201917/6/2026
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
ModificadaAlta (8.1)0.47%—Schneider-electric Powerscada Anywhere12/2/201817/6/2026
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social…
ModificadaMedia (5.5)0.46%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes.
ModificadaMedia (6.5)0.78%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
ModificadaMedia (6.5)0.56%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
ModificadaAlta (8.8)0.63%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social…
ModificadaMedia (5.9)1.6%—Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareSamsung X14j FirmwareZyxel Gs1900-10hp Firmware+16/4/201617/6/2026
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
ModificadaAlta (7.5)1.9%—Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware6/4/201617/6/2026
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348.
ModificadaAlta (7.8)1.8%—Schneider-electric CitectscadaSchneider-electric Powerlogic ScadaSchneider-electric Struxureware Powerscada ExpertSchneider-electric Struxureware Scada Expert Vijeo Citect26/2/201416/6/2026
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of…
ModificadaAlta (7.5)2.0%💥 ExploitPowerscripts Powerclan23/2/200916/6/2026
SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)0.96%💥 ExploitPowerscripts Powernews23/2/200916/6/2026
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
ModificadaAlta (7.5)3.0%💥 ExploitPowerscripts Powerphpboard28/3/200816/6/2026
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.
ModificadaMedia (6.8)2.9%💥 ExploitPowerscripts Powerbook28/3/200816/6/2026
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an…
ModificadaAlta (7.5)2.3%💥 ExploitPowerscripts Powernews13/2/200816/6/2026
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php…
ModificadaMedia (5)8.8%💥 ExploitPearson Education Powerschool21/2/200716/6/2026
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.
ModificadaMedia (5.1)3.0%💥 ExploitPowerscripts Powerclan23/12/200616/6/2026
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter.
ModificadaAlta (7.5)1.4%💥 ExploitPowerscripts Powerclan18/4/200616/6/2026
SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.
ModificadaAlta (7.5)2.9%💥 ExploitPowerscripts.org Powerdownload1/6/200516/6/2026
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.
ModificadaAlta (7.5)9.8%💥 ExploitPowerscripts Plusmail11/1/200016/6/2026
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.
Orbitaley — Vulnerabilidades