Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.61% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service. | |
| Pendiente de análisis | Crítica (9.8) | 0.83% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet… | |
| Modificada | Crítica (9.1) | 1.1% | — | Business-dnasolutions Topease | 30/11/2021 | 17/6/2026 | An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges. | |
| Modificada | Alta (8.8) | 1.1% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks. | |
| Modificada | Media (4.3) | 0.77% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format, which makes the affected attribute… | |
| Modificada | Media (4.3) | 1.0% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s date attribute(s) allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format into date fields, which leads to breaking the… | |
| Modificada | Media (6.5) | 1.1% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification privileges to insert arbitrarily long strings, eventually leading to exhaustion of the underlying… | |
| Modificada | Media (5.4) | 0.53% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated users with Object Modification privileges to inject arbitrary HTML and JavaScript in object attributes, which is then rendered in the… | |
| Modificada | Media (5.4) | 0.68% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticated remote attacker with Object Modification privileges to inject arbitrary HTML and JavaScript code in an object attribute, which is then… | |
| Modificada | Media (5.4) | 0.73% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object Modification privileges to insert arbitrary HTML without code execution. | |
| Modificada | Media (4.3) | 0.83% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said components in the front-end source code or… | |
| Modificada | Crítica (9.1) | 1.3% | — | Businessdnasolutions Topease | 30/11/2021 | 17/6/2026 | Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID. | |
| Modificada | Media (4.3) | 3.2% | — | Shoutcast Dnas | 16/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field. | |
| Modificada | Alta (10) | 3.1% | — | Shoutcast Dnas | 26/3/2001 | 16/6/2026 | Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description. |