Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.3% | — | Iobit Advanced Systemcare | 5/2/2021 | 17/6/2026 | The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The IOCTL codes can be found in the dispatch function: 0x8001E000,… | |
| Modificada | Crítica (9.8) | 1.6% | — | Sagemcom F@st 3686 Firmware | 26/1/2021 | 17/6/2026 | Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. | |
| Modificada | Crítica (10) | 6.2% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This… | |
| Modificada | Alta (8.7) | 1.7% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary files. | |
| Modificada | Crítica (9.8) | 2.6% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write… | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Media (6.7) | 0.18% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Powerstore Firmware | 5/1/2021 | 17/6/2026 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Media (6.5) | 1.5% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests. | |
| Modificada | Media (6.7) | 0.17% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the… | |
| Modificada | Media (6.7) | 0.26% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the… | |
| Modificada | Alta (7.8) | 0.26% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 5/1/2021 | 17/6/2026 | Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV… | |
| Modificada | Crítica (9.8) | 2.2% | — | Memcached Docker Image | 17/12/2020 | 17/6/2026 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Media (5.5) | 0.36% | — | Advancedsystemcare Advanced Systemcare | 3/12/2020 | 17/6/2026 | There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a constructed program to cause a computer crash (BSOD) | |
| Modificada | Media (5.3) | 1.1% | — | Sagemcom F@st 3486 Router Firmware | 27/11/2020 | 17/6/2026 | Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running. | |
| Modificada | Media (6.5) | 0.72% | — | Dell EMC Networker | 16/10/2020 | 17/6/2026 | Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner. | |
| Modificada | Media (6.5) | 0.72% | — | Dell EMC Networker | 16/10/2020 | 17/6/2026 | Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP. | |
| Modificada | Media (6.5) | 0.94% | — | Dell EMC Openmanage Integration FOR Microsoft System Center | 8/10/2020 | 17/6/2026 | Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive information from the logs. | |
| Modificada | Media (6.1) | 0.73% | — | Sagemcom F@st 3686 Firmware | 14/9/2020 | 9/7/2026 | Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Dell EMC Elastic Cloud Storage | 2/9/2020 | 17/6/2026 | Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system. | |
| Modificada | Alta (8.8) | 1.2% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 2/9/2020 | 17/6/2026 | Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files. | |
| Modificada | Alta (8.8) | 3.7% | — | Sagemcom F@st 5280 Router Firmware | 1/9/2020 | 17/6/2026 | Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value… | |
| Modificada | Media (5.3) | 1.0% | — | Dell EMC IsilonDell EMC Powerscale Onefs | 27/8/2020 | 17/6/2026 | Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart. | |
| Modificada | Media (4.8) | 0.35% | — | Emclient EM Client | 20/8/2020 | 17/6/2026 | eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowed a man-in-the-middle attacker to obtain an email-validated S/MIME certificate from a trusted CA and replace the public key of the entity to be impersonated. This enabled the attacker to… | |
| Modificada | Crítica (9.1) | 48% | 💥 Exploit | Dell EMC Openmanage Server Administrator | 28/7/2020 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access… |