Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.35% | — | Dell Elastic Cloud Storage | 22/5/2026 | 23/7/2026 | Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data. | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. | |
| Pendiente de análisis | Alta (8.7) | 0.84% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. | |
| Analizada | Alta (7.8) | 0.30% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.45% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in the OS. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (5.6) | 0.24% | — | Dell Elastic Cloud StorageDell Objectscale | 11/5/2026 | 17/6/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in… | |
| Analizada | Media (5.5) | 0.15% | — | Dell Elastic Cloud StorageDell Objectscale | 8/4/2026 | 24/7/2026 | Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure.… | |
| Aplazada | Baja (2.4) | 0.46% | — | Google Cloud StorageAICraftcms Craft CMSAICraftcms Google Cloud StorageAI | 18/3/2026 | 17/6/2026 | The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Google Cloud StorageAIGoogle Cloud SQLAI | 6/2/2026 | 17/6/2026 | The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in… | |
| Analizada | Media (5.5) | 0.10% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (4.4) | 0.14% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.18% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with remote access could potentially exploit this vulnerability to intercept and modify information in… | |
| Analizada | Alta (8.8) | 0.37% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.5) | 0.22% | — | Dell Elastic Cloud StorageDell Objectscale | 23/1/2026 | 17/6/2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Elastic Cloud StorageDell Objectscale | 4/8/2025 | 17/6/2026 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.5) | 0.13% | — | Dell Elastic Cloud StorageDell Objectscale | 15/7/2025 | 17/6/2026 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.5) | 0.13% | — | Dell Elastic Cloud StorageDell Objectscale | 17/4/2025 | 17/6/2026 | Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Elastic Cloud StorageDell Objectscale | 17/4/2025 | 17/6/2026 | Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (6.5) | 0.39% | — | Dell Elastic Cloud Storage | 26/12/2024 | 17/6/2026 | Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects. | |
| Analizada | Media (5.4) | 0.31% | — | Dell Elastic Cloud Storage | 25/12/2024 | 17/6/2026 | Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft. | |
| Analizada | Media (4.3) | 0.32% | — | Dell Elastic Cloud Storage | 9/12/2024 | 17/6/2026 | Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage. | |
| Analizada | Media (6.5) | 0.33% | — | Dell Elastic Cloud Storage | 18/7/2024 | 17/6/2026 | Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points. | |
| Aplazada | Media (6.5) | 0.35% | — | Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+1 | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and… | |
| Analizada | Media (6.5) | 0.46% | — | Dell Elastic Cloud Storage | 28/2/2024 | 17/6/2026 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace |