Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.6) | 2.2% | — | Dell EMC Isilonsd Management Server | 17/4/2019 | 17/6/2026 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user. | |
| Modificada | Crítica (9.6) | 2.2% | — | Dell EMC Isilonsd Management Server | 17/4/2019 | 17/6/2026 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user. | |
| Modificada | Crítica (9.8) | 5.9% | — | Dell EMC Networker | 1/4/2019 | 17/6/2026 | EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with… | |
| Modificada | Alta (8.1) | 0.80% | — | Dell EMC Networking Os10 | 28/3/2019 | 17/6/2026 | Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauthenticated remote attacker with the knowledge of the default keys may potentially be able to intercept communications or… | |
| Modificada | Alta (7.2) | 2.0% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 13/3/2019 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks. | |
| Modificada | Media (5.3) | 1.1% | — | Sagemcom F@st 5260 Firmware | 5/3/2019 | 17/6/2026 | Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small. | |
| Modificada | Media (6.1) | 1.0% | — | Semcosoft | 23/2/2019 | 17/6/2026 | A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary web scripts or HTML via the username parameter to the Login Form. | |
| Modificada | Alta (7.8) | 0.94% | — | Dell EMC Vnx2 Firmware | 7/2/2019 | 17/6/2026 | VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability. | |
| Modificada | Media (4.8) | 0.56% | — | Sem-cms Semcms | 10/12/2018 | 17/6/2026 | SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI. | |
| Modificada | Media (6.7) | 1.0% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute… | |
| Modificada | Media (6.5) | 0.83% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private… | |
| Modificada | Media (6.1) | 1.8% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this… | |
| Modificada | Crítica (9.8) | 9.9% | — | Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection | 26/11/2018 | 17/6/2026 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit… | |
| Modificada | Alta (7.1) | 0.41% | — | Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines | 13/11/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system… | |
| Modificada | Media (5.5) | 0.42% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 13/11/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI. | |
| Modificada | Alta (8.8) | 1.8% | — | Dell EMC Integrated Data Protection Appliance | 2/11/2018 | 17/6/2026 | Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may… | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 30/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter. | |
| Modificada | Media (5.4) | 0.56% | — | Sem-cms Semcms | 30/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter. | |
| Modificada | Media (6.1) | 0.80% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI. | |
| Modificada | Alta (8.8) | 0.52% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI. |