Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.5% | — | IBM Spectrum VirtualizeIBM Spectrum Virtualize FOR Public CloudIBM Storwize V3500 SoftwareIBM Storwize V3700 Software+6 | 21/10/2021 | 17/6/2026 | IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229. | |
| Modificada | Alta (8.1) | 1.6% | — | IBM Spectrum VirtualizeIBM Flashsystem V5000 FirmwareIBM Flashsystem V7200 FirmwareIBM Flashsystem V9000 Firmware+7 | 17/8/2020 | 17/6/2026 | IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678. | |
| Modificada | Media (5.3) | 0.81% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM… | |
| Modificada | Media (5.3) | 1.3% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM… | |
| Modificada | Media (6.5) | 1.6% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force… | |
| Modificada | Media (6.5) | 1.4% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account… | |
| Modificada | Alta (7.6) | 1.2% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a… | |
| Modificada | Media (5.4) | 0.96% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus… | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566. | |
| Modificada | Alta (8.8) | 0.91% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Modificada | Alta (7.5) | 2.5% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473. | |
| Modificada | Crítica (9.8) | 3.5% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Flashsystem V9000 FirmwareIBM SAN Volume Controller Firmware | 13/11/2017 | 17/6/2026 | A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-Force ID: 134531. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… |