Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.68% | — | Dell EMC Networker | 1/8/2018 | 17/6/2026 | Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote AMQP service. An unauthenticated attacker… | |
| Modificada | Crítica (9.8) | 1.6% | — | Golemcms Project Golemcms | 24/7/2018 | 17/6/2026 | GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql. | |
| Modificada | Media (6.1) | 1.3% | — | EMC RSA Identity Governance AND Lifecycle | 13/7/2018 | 17/6/2026 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable web… | |
| Modificada | Alta (8.8) | 2.5% | — | EMC RSA Identity Governance AND Lifecycle | 13/7/2018 | 17/6/2026 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security Policies. Once bypassed, a malicious user could… | |
| Modificada | Alta (7.3) | 0.45% | — | EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance | 11/7/2018 | 17/6/2026 | RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted… | |
| Modificada | Crítica (9.1) | 1.5% | — | Memcachier Memjs | 5/7/2018 | 17/6/2026 | `memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage. | |
| Modificada | Alta (7.5) | 0.98% | — | Gemchain Project Gemchain | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for GEMCHAIN (GEM), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 4.0% | — | Dellemc Elastic Cloud Storage | 3/7/2018 | 17/6/2026 | Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying specially crafted S3 requests. | |
| Modificada | Alta (7.5) | 2.6% | — | EMC RSA Certificate Manager | 3/7/2018 | 17/6/2026 | RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain… | |
| Modificada | Media (6.5) | 0.45% | — | Dell EMC Idrac Service Module | 26/6/2018 | 17/6/2026 | Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host… | |
| Modificada | Media (6.1) | 2.0% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim Security Console administrator to supply malicious HTML or JavaScript code to a… | |
| Modificada | Media (6.1) | 1.5% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console… | |
| Modificada | Media (6.5) | 2.6% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 29/5/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the Boxmgmt CLI. An authenticated malicious user with boxmgmt privileges may potentially exploit this vulnerability to read RPA files. Note that files that require root… | |
| Modificada | Alta (8.8) | 1.5% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 29/5/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in… | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 29/5/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege. | |
| Modificada | Media (6.5) | 1.0% | — | Pivotal Software Windows Stemcells | 17/5/2018 | 17/6/2026 | Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials. | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Media (5.9) | 5.5% | — | Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+7 | 16/5/2018 | 17/6/2026 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a… | |
| Modificada | Alta (7.2) | 3.3% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 8/5/2018 | 17/6/2026 | Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system where Dell EMC Unity is installed. | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… | |
| Modificada | Alta (8.8) | 0.51% | — | Chemcms Project Chemcms | 22/4/2018 | 17/6/2026 | ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account. | |
| Modificada | Alta (8) | 0.53% | — | EMC Vipr Controller | 18/4/2018 | 17/6/2026 | Dell EMC ViPR Controller, versions after 3.0.0.38, contain an information exposure vulnerability in the VRRP. VRRP defaults to an insecure configuration in Linux's keepalived component which sends the cluster password in plaintext through multicast. A malicious user, having access to the vCloud subnet where ViPR is… | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Dell EMC AvamarDell EMC Integrated Data Protection Appliance | 9/4/2018 | 17/6/2026 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS)… | |
| Modificada | Alta (7.2) | 2.5% | — | Eyrie RemctlDebian Linux | 3/4/2018 | 17/6/2026 | remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution. | |
| Modificada | Alta (7.5) | 1.5% | — | Dell EMC Scaleio | 27/3/2018 | 17/6/2026 | Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access to LIA and knowledge of the LIA… |