Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
ModificadaMedia (5.5)0.44%—Dell EMC Secure Remote Services18/10/201817/6/2026
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the…
ModificadaAlta (7.8)0.37%—EMC Secure Remote Services18/10/201817/6/2026
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an authenticated malicious user to utilize the file contents to potentially elevate their privileges.
ModificadaAlta (7.8)0.37%—EMC Secure Remote Services18/10/201817/6/2026
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the…
ModificadaAlta (7.8)0.39%—Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment5/10/201817/6/2026
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code…
ModificadaAlta (8.1)1.6%—Lenovoemc Firmware28/9/201817/6/2026
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a…
ModificadaAlta (8.1)1.6%—Lenovoemc Firmware28/9/201817/6/2026
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c…
ModificadaAlta (8.1)4.1%💥 PoCLenovoemc Firmware28/9/201817/6/2026
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires…
ModificadaMedia (6.5)0.97%—Lenovoemc Firmware28/9/201817/6/2026
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
ModificadaCrítica (9.8)5.3%—EMC Esrs Policy Manager28/9/201817/6/2026
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.
ModificadaAlta (8.1)2.5%—Dell EMC Unity FirmwareDell EMC Unityvsa28/9/201817/6/2026
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker…
ModificadaMedia (6.5)1.6%—Dell EMC Unity FirmwareDell EMC Unityvsa28/9/201817/6/2026
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control…
ModificadaMedia (6.1)1.1%—Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment28/9/201817/6/2026
Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by…
ModificadaMedia (4.7)1.5%—RSA Authentication ManagerEMC RSA Authentication Manager28/9/201817/6/2026
RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security Console page. A remote, unauthenticated malicious user, with the knowledge of a target user's anti-CSRF token, could potentially exploit this vulnerability by tricking a victim Security Console user…
ModificadaMedia (6.1)2.0%—RSA Authentication ManagerEMC RSA Authentication Manager28/9/201817/6/2026
RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or…
ModificadaMedia (4.8)1.1%—EMC RSA Authentication ManagerRSA Authentication Manager28/9/201817/6/2026
RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console…
ModificadaMedia (6.5)1.9%💥 PoCIobit Advanced Systemcare26/9/201817/6/2026
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and…
ModificadaMedia (6.5)1.3%💥 PoCIobit Advanced Systemcare26/9/201817/6/2026
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read physical memory.
ModificadaAlta (8.8)2.0%💥 PoCIobit Advanced Systemcare26/9/201817/6/2026
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for input.
ModificadaAlta (7.5)1.8%—EMC Isilon OnefsEMC Isilonsd Edge18/9/201817/6/2026
Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonSD Edge versions 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 contain a remote process crash vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash…
ModificadaAlta (7.5)0.76%—Dell EMC Vplex Geosynchrony11/9/201817/6/2026
Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic.
ModificadaMedia (4.8)0.56%—Chemcms Project Chemcms2/9/201817/6/2026
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
ModificadaCrítica (9.1)5.0%—EMC RSA NetwitnessEMC RSA Security Analytics24/8/201817/6/2026
RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template injection vulnerability due to insecure configuration of the template engine used in the product. A remote authenticated malicious RSA NetWitness Server user with an Admin or…
ModificadaAlta (8.1)2.1%—Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance10/8/201817/6/2026
Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain…
Orbitaley — Vulnerabilidades