Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.15% | — | Dell Boot Optimized Server StorageAI | 28/9/2026 | 28/9/2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to… | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Payloadcms Storage-vercel-blobAI | 25/9/2026 | 30/9/2026 | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | LibstoragemgmtAI | 21/9/2026 | 24/9/2026 | A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in… | |
| Pendiente de análisis | Media (4.4) | 0.17% | — | Containers StorageAI | 15/9/2026 | 2/10/2026 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer. | |
| Pendiente de análisis | Baja (2.3) | 0.25% | — | Netapp StoragegridAI | 28/8/2026 | 1/9/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service. | |
| Rechazada | Sin puntuar | — | — | 6storage RentalsAI | 24/8/2026 | 24/8/2026 | Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID. | |
| Aplazada | Alta (7.2) | 0.68% | — | Flow-likeAIMicrosoft Azure Blob StorageAI | 19/8/2026 | 18/9/2026 | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member lacks `ReadFiles` and `WriteFiles`. The… | |
| Analizada | Alta (7.2) | 0.94% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5… | |
| Analizada | Alta (8) | 0.83% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |
| Analizada | Alta (7.2) | 0.74% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of… | |
| Aplazada | Crítica (9.8) | 0.84% | — | 6storage RentalsAI | 15/8/2026 | 20/8/2026 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification,… | |
| Analizada | Media (5.5) | 0.16% | — | IBM Storage Scale | 13/8/2026 | 18/8/2026 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM… | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Storage Scale | 13/8/2026 | 17/8/2026 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Azure Storage Explorer | 11/8/2026 | 17/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 2.3% | — | Dell Virtual Storage Integrator | 6/8/2026 | 7/8/2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's… | |
| Analizada | Crítica (9.8) | 0.62% | — | Dell Virtual Storage Integrator | 6/8/2026 | 7/8/2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered… | |
| Pendiente de análisis | Crítica (9.5) | 2.1% | — | Rails Action PackAILibvipsAIRubyonrails Active StorageAI | 30/7/2026 | 10/9/2026 | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured… | |
| Analizada | Alta (8.7) | 0.52% | — | Progress Sharefile Storage Zones Controller | 21/7/2026 | 3/9/2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Storage Protect | 17/7/2026 | 11/8/2026 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Analizada | Crítica (9.8) | 0.52% | — | Proxmox Libpve-storage-perl | 17/7/2026 | 11/8/2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| Aplazada | Alta (8.5) | 0.16% | — | Gigabyte Control CenterAIGigabyte Mbstorage DramAI | 13/7/2026 | 14/7/2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and… | |
| Analizada | Crítica (10) | 0.64% | — | Appium/storage-plugin | 8/7/2026 | 26/8/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path… | |
| Pendiente de análisis | Media (6.9) | 0.47% | — | Microsoft Azure Blob StorageAI | 3/7/2026 | 6/7/2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container. | |
| Aplazada | Crítica (10) | 4.4% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary… | |
| Aplazada | Crítica (10) | 4.2% | — | Stonefly Storage ConcentratorAI | 30/6/2026 | 1/7/2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is… |