Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.58%—Microsoft Azure Cyclecloud8/9/202629/9/2026
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.80%—Microsoft Azure Cyclecloud11/8/202617/8/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Azure Cyclecloud11/8/202617/8/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (6)0.26%—Lenovo LecloudAI15/10/202517/6/2026
A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.
AplazadaMedia (5)0.23%—FilecloudAI17/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
AnalizadaCrítica (9.9)2.3%—Microsoft Azure Cyclecloud12/11/202417/6/2026
Azure CycleCloud Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.6%—Microsoft Azure Cyclecloud10/9/202410/8/2026
Azure CycleCloud Remote Code Execution Vulnerability
AnalizadaAlta (7.8)0.51%—Microsoft Azure Cyclecloud13/8/202417/6/2026
Azure CycleCloud Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.6%—Microsoft Azure Cyclecloud9/7/202417/6/2026
Azure CycleCloud Elevation of Privilege Vulnerability
AnalizadaAlta (8.8)2.0%—Microsoft Azure Cyclecloud9/4/202417/6/2026
Azure CycleCloud Elevation of Privilege Vulnerability
ModificadaAlta (7.5)0.63%—Lenovo Lecloud8/11/202317/6/2026
Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure.
ModificadaAlta (7.8)1.2%—Helecloud Puppet-facter26/1/202317/6/2026
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
ModificadaAlta (7.2)2.8%—Filecloud23/11/202217/6/2026
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.
ModificadaAlta (8.8)0.71%—Microsoft Azure Cyclecloud9/11/202210/8/2026
Azure CycleCloud Elevation of Privilege Vulnerability
ModificadaMedia (6.5)0.73%—Filecloud15/6/202217/6/2026
A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Upgrading to version 21.3.5.18513 is able to address this issue. It is recommended to…
ModificadaMedia (5.3)0.81%—Filecloud24/2/202217/6/2026
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.
ModificadaAlta (8.8)0.39%—Filecloud16/2/202217/6/2026
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
ModificadaAlta (8.8)3.3%—Filecloud16/2/202217/6/2026
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
ModificadaAlta (7.8)0.82%—Microsoft Azure Cyclecloud12/8/202110/8/2026
Azure CycleCloud Elevation of Privilege Vulnerability
ModificadaAlta (7.8)0.59%—Microsoft Azure Cyclecloud12/8/202110/8/2026
Azure CycleCloud Elevation of Privilege Vulnerability
ModificadaMedia (5.3)1.4%—Filecloud2/10/202017/6/2026
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
ModificadaAlta (8.8)0.86%—Filecloud13/7/201817/6/2026
CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.