Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.15% | — | Unistal Systems PVT LTD Protegent 360AI | 23/7/2026 | 30/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Alta (7.8) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function | |
| Aplazada | Alta (7.8) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Media (5.5) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 | |
| Analizada | Media (5.3) | 0.30% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.8) | 0.86% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Media (6.5) | 0.45% | — | Dell Unisphere FOR Powermax | 10/7/2026 | 16/7/2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. | |
| Analizada | Alta (7.5) | 0.25% | — | Dell Unisphere FOR Powermax Virtual Appliance | 22/5/2026 | 23/7/2026 | Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp | |
| Analizada | Alta (7) | 0.99% | — | Unisys Webperfect Image Suite | 14/4/2026 | 24/7/2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-account hashes. Attackers… | |
| Analizada | Alta (7) | 0.88% | — | Unisys Webperfect Image Suite | 14/4/2026 | 24/7/2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques. Attackers can… | |
| Aplazada | Alta (8.7) | 0.41% | — | Unisharp Laravel File ManagerAI | 5/4/2026 | 24/7/2026 | UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by… | |
| Analizada | Alta (8.1) | 0.53% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files. | |
| Analizada | Media (6.5) | 0.40% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (8.1) | 0.46% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. | |
| Analizada | Alta (8.8) | 0.51% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files. | |
| Analizada | Alta (8.8) | 0.43% | — | Dell Unisphere FOR Powermax | 19/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Media (5.4) | 0.28% | — | Dell Unisphere FOR PowermaxAI | 17/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in… | |
| Aplazada | Media (5.4) | 0.17% | — | Dell Unisphere FOR Powermax VappAI | 17/2/2026 | 17/6/2026 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript… | |
| Aplazada | Alta (8.8) | 0.73% | — | Pacom Unison ClientAI | 11/2/2026 | 5/7/2026 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution. | |
| Modificada | Alta (8.8) | 0.65% | — | Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance | 22/1/2026 | 17/6/2026 | Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (7.1) | 0.28% | — | Dell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance | 6/1/2026 | 30/9/2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control. | |
| Aplazada | Media (5.4) | 0.19% | — | Talentyazilim UnisAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS. This issue affects UNIS: before 42957. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Talentyazilim UnisAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection. This issue affects UNIS: before 42321. | |
| Rechazada | Sin puntuar | — | — | Unisharp Laravel-filemanagerAI | 5/9/2025 | 5/9/2025 | Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager. | |
| Aplazada | Crítica (9.6) | 0.56% | — | Unisite CMSAI | 4/8/2025 | 17/6/2026 | Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload… |