Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | — | IBM Elastic Storage ServerIBM Elastic Storage System | 24/3/2021 | 17/6/2026 | IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM X-Force ID: 193486. | |
| Modificada | Media (5.5) | 0.35% | — | IBM Elastic Storage ServerIBM Spectrum Scale | 20/10/2020 | 17/6/2026 | IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Elastic Storage Server | 24/8/2020 | 17/6/2026 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment while configuring some of the network services. IBM X-Force ID: 179165. | |
| Modificada | Media (5.5) | 0.32% | — | IBM Elastic Storage Server | 24/8/2020 | 17/6/2026 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment or upgrade pertaining to xcat services. IBM X-Force ID: 179163. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Elastic Storage Server | 19/8/2020 | 17/6/2026 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific services are enabled. IBM X-Force ID: 179162. | |
| Modificada | Media (4.8) | 3.8% | — | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Media (6.2) | 0.37% | — | IBM Elastic Storage Server | 21/6/2017 | 17/6/2026 | IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node and utilize direct I/O to perform a read or a write to a Spectrum… | |
| Modificada | Alta (7) | 0.32% | — | IBM General Parallel File System Storage ServerIBM Spectrum Scale | 29/6/2016 | 17/6/2026 | IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command. | |
| Modificada | Alta (8.4) | 0.50% | — | IBM Elastic Storage ServerIBM General Parallel File System Storage Server | 19/6/2016 | 17/6/2026 | IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program. | |
| Modificada | Media (6.5) | 1.7% | — | Redhat Gluster Storage Management ConsoleRedhat Gluster Storage ServerRedhat Storage Native Client | 7/6/2016 | 17/6/2026 | The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Baja (3.6) | 0.38% | — | Redhat Storage Server | 4/10/2013 | 16/6/2026 | Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp. | |
| Analizada | Alta (8.8) | 69% | ⚠ Explotación activa | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+11 | 26/6/2013 | 16/6/2026 | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute… | |
| Analizada | Media (6.5) | 6.7% | ⚠ Explotación activa | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+14 | 16/5/2013 | 16/6/2026 | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information… | |
| Modificada | Baja (2.1) | 0.32% | — | GlusterfsRedhat Storage Management ConsoleRedhat Storage Native ClientRedhat Storage Server | 9/4/2013 | 16/6/2026 | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different… | |
| Modificada | Crítica (9.8) | 6.6% | — | Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+3 | 22/10/2012 | 16/6/2026 | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object. | |
| Modificada | Media (6.5) | 14% | — | Librdf RaptorLibreofficeApache OpenofficeFedoraproject Fedora+9 | 17/6/2012 | 16/6/2026 | Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | PHPFedoraproject FedoraDebian LinuxHp-ux+13 | 11/5/2012 | 16/6/2026 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of… | |
| Modificada | Alta (7.8) | 0.49% | — | Christophe.varoqui Multipath-toolsFedoraproject FedoraDebian LinuxAvaya Intuity Audix LX+7 | 30/3/2009 | 16/6/2026 | The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send… | |
| Modificada | Media (6.5) | 3.1% | — | Avaya Messaging Storage Server | 9/7/2008 | 16/6/2026 | Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelCanonical Ubuntu LinuxNovell Linux DesktopOpensuse+11 | 9/7/2008 | 16/6/2026 | The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4)… | |
| Modificada | Alta (7.8) | 1.6% | — | Avaya Message NetworkingAvaya Messaging Storage Server | 5/11/2007 | 16/6/2026 | Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vectors related to "input validation." | |
| Modificada | Media (5.5) | 0.29% | — | BusyboxAvaya Aura Application Enablement ServicesAvaya Aura SIP Enablement ServicesAvaya Message Networking+1 | 4/4/2006 | 16/6/2026 | BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. | |
| Modificada | Media (5) | 2.4% | — | Avaya Modular Messaging Message Storage Server | 22/12/2005 | 16/6/2026 | POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets. |