Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 23% | — | Sagemcom F@st 3890 FirmwareSagemcom F@st 3686 FirmwareNetgear Cg3700emr FirmwareNetgear C6250emr Firmware+3 | 9/1/2020 | 17/6/2026 | Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to… | |
| Modificada | Media (6.5) | 1.1% | — | EMC RSA Authentication Manager | 3/1/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message. | |
| Modificada | Media (4.8) | 0.56% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 3/12/2019 | 17/6/2026 | RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a… | |
| Modificada | Crítica (10) | 4.9% | — | Dell EMC Storage Monitoring AND Reporting | 26/11/2019 | 17/6/2026 | Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host. | |
| Modificada | Alta (8.1) | 1.1% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 9/10/2019 | 17/6/2026 | Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4 contain an Incorrect Permission Assignment for Critical Resource vulnerability. A remote authenticated malicious user potentially could exploit this… | |
| Modificada | Media (4.9) | 0.60% | — | Dell Bsafe Crypto-c-micro-editionEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at… | |
| Modificada | Alta (7.5) | 1.4% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing… | |
| Modificada | Crítica (9.8) | 1.9% | — | Dell EMC Elastic Cloud Storage | 27/9/2019 | 17/6/2026 | Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts. | |
| Modificada | Media (4.8) | 0.78% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through… | |
| Modificada | Alta (8.8) | 2.1% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system. | |
| Modificada | Alta (7.2) | 0.70% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other… | |
| Modificada | Media (6.1) | 1.1% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating EnvironmentDell EMC Vnxe3200 Firmware | 3/9/2019 | 17/6/2026 | Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this… | |
| Modificada | Alta (7.4) | 0.74% | — | Dell EMC Enterprise Copy Data Management | 3/9/2019 | 17/6/2026 | Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's… | |
| Modificada | Alta (7.5) | 2.6% | — | Memcached | 30/8/2019 | 17/6/2026 | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c. | |
| Modificada | Media (6.5) | 0.65% | — | Dell EMC Powerconnect 8024 FirmwareDell EMC Powerconnect 7000 FirmwareDell EMC Powerconnect M6348 FirmwareDell EMC Powerconnect M6220 Firmware+2 | 20/8/2019 | 17/6/2026 | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may… | |
| Modificada | Alta (7.5) | 2.4% | — | Emca Energy Logserver | 5/8/2019 | 17/6/2026 | The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter. | |
| Modificada | Alta (7.8) | 0.34% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 18/7/2019 | 17/6/2026 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the… | |
| Modificada | Media (4.3) | 1.1% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 18/7/2019 | 17/6/2026 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator could potentially exploit this vulnerability to edit quota configuration of other users. | |
| Modificada | Crítica (9.1) | 1.8% | — | Dell EMC Openmanage Server Administrator | 6/6/2019 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any… | |
| Modificada | Alta (7.5) | 3.8% | — | Dell EMC Openmanage Server Administrator | 6/6/2019 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type… | |
| Modificada | Media (6.7) | 0.66% | — | Dell EMC RecoverpointDell Recoverpoint FOR Virtual Machines | 15/5/2019 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may potentially be able to execute arbitrary commands as root. | |
| Modificada | Alta (7.5) | 3.0% | — | MemcachedCanonical Ubuntu Linux | 29/4/2019 | 17/6/2026 | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c. | |
| Modificada | Alta (7.5) | 2.6% | — | Dell EMC Openmanage Server Administrator | 25/4/2019 | 17/6/2026 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to cause the application to compress each of the requested bytes, resulting in a crash due to excessive… | |
| Modificada | Media (4.9) | 3.5% | — | Dell EMC Openmanage Server Administrator | 25/4/2019 | 17/6/2026 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by exploiting insufficient sanitization of input… | |
| Modificada | Alta (7.2) | 1.3% | — | Sem-cms Semcms | 25/4/2019 | 17/6/2026 | An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete. |