Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%—IBM Elastic Storage ServerIBM Elastic Storage System24/3/202117/6/2026
IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM X-Force ID: 193486.
ModificadaMedia (5.5)0.35%—IBM Elastic Storage ServerIBM Spectrum Scale20/10/202017/6/2026
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.
ModificadaMedia (6.5)1.1%—IBM Elastic Storage Server24/8/202017/6/2026
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment while configuring some of the network services. IBM X-Force ID: 179165.
ModificadaMedia (5.5)0.32%—IBM Elastic Storage Server24/8/202017/6/2026
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment or upgrade pertaining to xcat services. IBM X-Force ID: 179163.
ModificadaMedia (6.5)1.0%—IBM Elastic Storage Server19/8/202017/6/2026
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific services are enabled. IBM X-Force ID: 179162.
ModificadaMedia (4.8)3.8%—Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+1321/9/201717/6/2026
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
ModificadaMedia (6.2)0.37%—IBM Elastic Storage Server21/6/201717/6/2026
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node and utilize direct I/O to perform a read or a write to a Spectrum…
ModificadaAlta (7)0.32%—IBM General Parallel File System Storage ServerIBM Spectrum Scale29/6/201617/6/2026
IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.
ModificadaAlta (8.4)0.50%—IBM Elastic Storage ServerIBM General Parallel File System Storage Server19/6/201617/6/2026
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
ModificadaMedia (6.5)1.7%—Redhat Gluster Storage Management ConsoleRedhat Gluster Storage ServerRedhat Storage Native Client7/6/201617/6/2026
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
ModificadaBaja (3.6)0.38%—Redhat Storage Server4/10/201316/6/2026
Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp.
AnalizadaAlta (8.8)69%⚠ Explotación activaMozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+1126/6/201316/6/2026
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute…
AnalizadaMedia (6.5)6.7%⚠ Explotación activaMozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+1416/5/201316/6/2026
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information…
ModificadaBaja (2.1)0.32%—GlusterfsRedhat Storage Management ConsoleRedhat Storage Native ClientRedhat Storage Server9/4/201316/6/2026
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different…
ModificadaCrítica (9.8)6.6%—Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+322/10/201216/6/2026
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
ModificadaMedia (6.5)14%—Librdf RaptorLibreofficeApache OpenofficeFedoraproject Fedora+917/6/201216/6/2026
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
AnalizadaCrítica (9.8)100%⚠ Explotación activaPHPFedoraproject FedoraDebian LinuxHp-ux+1311/5/201216/6/2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of…
ModificadaAlta (7.8)0.49%—Christophe.varoqui Multipath-toolsFedoraproject FedoraDebian LinuxAvaya Intuity Audix LX+730/3/200916/6/2026
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send…
ModificadaMedia (6.5)3.1%—Avaya Messaging Storage Server9/7/200816/6/2026
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors…
ModificadaAlta (7.8)0.43%—Linux KernelCanonical Ubuntu LinuxNovell Linux DesktopOpensuse+119/7/200816/6/2026
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4)…
ModificadaAlta (7.8)1.6%—Avaya Message NetworkingAvaya Messaging Storage Server5/11/200716/6/2026
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vectors related to "input validation."
ModificadaMedia (5.5)0.29%—BusyboxAvaya Aura Application Enablement ServicesAvaya Aura SIP Enablement ServicesAvaya Message Networking+14/4/200616/6/2026
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
ModificadaMedia (5)2.4%—Avaya Modular Messaging Message Storage Server22/12/200516/6/2026
POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.