Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.58% | — | Microsoft Azure Cyclecloud | 8/9/2026 | 29/9/2026 | Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Azure Cyclecloud | 14/7/2026 | 22/7/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Cyclecloud | 14/7/2026 | 22/7/2026 | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6) | 0.26% | — | Lenovo LecloudAI | 15/10/2025 | 17/6/2026 | A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure. | |
| Aplazada | Media (5) | 0.23% | — | FilecloudAI | 17/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Analizada | Crítica (9.9) | 2.3% | — | Microsoft Azure Cyclecloud | 12/11/2024 | 17/6/2026 | Azure CycleCloud Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Azure Cyclecloud | 10/9/2024 | 10/8/2026 | Azure CycleCloud Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.51% | — | Microsoft Azure Cyclecloud | 13/8/2024 | 17/6/2026 | Azure CycleCloud Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.6% | — | Microsoft Azure Cyclecloud | 9/7/2024 | 17/6/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Azure Cyclecloud | 9/4/2024 | 17/6/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 0.63% | — | Lenovo Lecloud | 8/11/2023 | 17/6/2026 | Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure. | |
| Modificada | Alta (7.8) | 1.2% | — | Helecloud Puppet-facter | 26/1/2023 | 17/6/2026 | All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. | |
| Modificada | Alta (7.2) | 2.8% | — | Filecloud | 23/11/2022 | 17/6/2026 | FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request. | |
| Modificada | Alta (8.8) | 0.71% | — | Microsoft Azure Cyclecloud | 9/11/2022 | 10/8/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 0.73% | — | Filecloud | 15/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Upgrading to version 21.3.5.18513 is able to address this issue. It is recommended to… | |
| Modificada | Media (5.3) | 0.81% | — | Filecloud | 24/2/2022 | 17/6/2026 | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths. | |
| Modificada | Alta (8.8) | 0.39% | — | Filecloud | 16/2/2022 | 17/6/2026 | In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF). | |
| Modificada | Alta (8.8) | 3.3% | — | Filecloud | 16/2/2022 | 17/6/2026 | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). | |
| Modificada | Alta (7.8) | 0.82% | — | Microsoft Azure Cyclecloud | 12/8/2021 | 10/8/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.59% | — | Microsoft Azure Cyclecloud | 12/8/2021 | 10/8/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 1.4% | — | Filecloud | 2/10/2020 | 17/6/2026 | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration. | |
| Modificada | Alta (8.8) | 0.86% | — | Filecloud | 13/7/2018 | 17/6/2026 | CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. |