Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.73% | — | Stonefly Storage Concentrator | 12/7/2024 | 17/6/2026 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information. | |
| Aplazada | Alta (8.8) | 1.3% | — | Stonefly Storage ConcentratorAI | 12/7/2024 | 17/6/2026 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution. | |
| Modificada | Media (4.6) | 0.25% | — | IBM Storage Virtualize | 8/7/2024 | 17/6/2026 | IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935. | |
| Modificada | Alta (7.5) | 0.41% | — | IBM Storage Defender Resiliency Service | 28/6/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869. | |
| Modificada | Media (6.5) | 0.25% | — | IBM Storage Defender | 28/6/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678. | |
| Aplazada | Media (5.3) | 0.20% | — | Vmware Cloud Director Object Storage ExtensionAI | 27/6/2024 | 17/6/2026 | VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access to web/proxy server logging may be able to obtain sensitive information from URLs that are logged. | |
| Aplazada | Media (4.4) | 0.14% | — | Hitachi Storage Provider FOR Vmware VcenterAI | 25/6/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4. | |
| Modificada | Alta (7.7) | 0.47% | — | IBM Storage Protect FOR Virtual Environments | 19/6/2024 | 17/6/2026 | IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change… | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Storagegrid | 14/6/2024 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation. | |
| Modificada | Alta (7.5) | 2.5% | — | Microsoft Azure Storage Data Movement Library | 11/6/2024 | 20/7/2026 | Azure Storage Movement Client Library Denial of Service Vulnerability | |
| Modificada | Media (5.5) | 0.50% | — | Linux KernelNetapp Converged Systems Advisor AgentNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+6 | 30/5/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4(). | |
| Aplazada | Alta (7.8) | 0.21% | — | Asustek USB 3.0 Boost Storage DriverAI | 22/5/2024 | 17/6/2026 | An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 PoC | IBM Storage Fusion HCI | 14/5/2024 | 17/6/2026 | IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807. | |
| Modificada | Alta (7.4) | 0.40% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+7 | 6/5/2024 | 17/6/2026 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present… | |
| Analizada | Alta (8.8) | 0.37% | — | IBM Storage Scale | 30/4/2024 | 17/6/2026 | IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208. | |
| Analizada | Media (6.5) | 0.22% | — | Oracle ZFS Storage Appliance KIT | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Analizada | Baja (3.7) | 0.75% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp Data Infrastructure Insights Acquisition UnitNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows… | |
| Analizada | Baja (3.7) | 1.3% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2 and 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.7) | 0.91% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition:… | |
| Analizada | Baja (3.7) | 1.4% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.1) | 0.85% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Baja (2.5) | 0.35% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to… | |
| Modificada | Baja (3.1) | 0.86% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Baja (2.5) | 0.35% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to… |