Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 3.2% | — | Proxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI | 1/9/2026 | 8/9/2026 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login… | |
| Aplazada | Media (6.5) | 0.34% | — | Proxmox Virtual EnvironmentAIProxmox Qemu-serverAI | 17/7/2026 | 17/7/2026 | Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API. | |
| Aplazada | Alta (7.2) | 0.39% | — | Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI | 17/7/2026 | 17/7/2026 | A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call… | |
| Aplazada | Media (6.1) | 0.25% | — | Proxmox Virtual EnvironmentAI | 17/7/2026 | 17/7/2026 | A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Media (5.4) | 0.29% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side… | |
| Analizada | Media (5.4) | 0.29% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session… | |
| Analizada | Media (5.4) | 0.34% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected… | |
| Analizada | Alta (7.5) | 0.23% | — | IBM Storage Protect FOR Virtual EnvironmentsIBM Storage Protect | 27/1/2025 | 17/6/2026 | IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Aplazada | Alta (8.2) | 0.36% | — | Proxmox Virtual EnvironmentAI | 25/9/2024 | 17/6/2026 | Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or 'VM.Monitor' privileges to download arbitrary host files via the API. When handling the result from a… | |
| Modificada | Alta (7.7) | 0.47% | — | IBM Storage Protect FOR Virtual Environments | 19/6/2024 | 17/6/2026 | IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change… | |
| Modificada | Alta (8.8) | 1.4% | — | Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment | 27/9/2023 | 17/6/2026 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. | |
| Modificada | Media (4.7) | 0.13% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual Environments | 19/7/2023 | 17/6/2026 | IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012. | |
| Modificada | Crítica (9) | 1.3% | — | Proxmox Virtual Environment | 14/12/2022 | 9/7/2026 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/. | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,… | |
| Modificada | Alta (7.1) | 1.4% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow… | |
| Modificada | Alta (7.8) | 0.21% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 26/4/2021 | 17/6/2026 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811. | |
| Modificada | Media (5.3) | 1.2% | — | Proxmox Virtual Environment | 27/1/2020 | 17/6/2026 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability | |
| Modificada | Media (4.4) | 0.31% | — | IBM Spectrum ProtectIBM Spectrum Protect FOR Virtual Environments | 25/11/2019 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551. | |
| Modificada | Media (4.7) | 0.22% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968. | |
| Modificada | Media (5.5) | 0.30% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+2 | 12/11/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870. | |
| Modificada | Media (5.5) | 0.29% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Space ManagementIBM Tivoli Storage Manager FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696. | |
| Modificada | Alta (7.5) | 0.97% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649. | |
| Modificada | Alta (8.1) | 0.91% | — | IBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 4/4/2018 | 17/6/2026 | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new… |