Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 8.2% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of… | |
| Modificada | Alta (8.8) | 5.5% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any… | |
| Modificada | Crítica (9.8) | 4.7% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the… | |
| Modificada | Crítica (9.8) | 3.0% | — | EMC Avamar Server | 21/6/2017 | 17/6/2026 | In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system. | |
| Modificada | Crítica (9.8) | 3.3% | — | EMC Avamar Server | 21/6/2017 | 17/6/2026 | In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates,… | |
| Modificada | Media (6.7) | 0.39% | — | EMC Avamar Data StoreEMC Avamar Virtual Edition | 25/1/2017 | 17/6/2026 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and 7.3.1 contain a vulnerability that may allow malicious administrators to compromise Avamar servers. | |
| Modificada | Alta (8.4) | 0.38% | — | EMC Avamar Data StoreEMC Avamar Server Virtual Edition | 15/11/2016 | 17/6/2026 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to potentially be compromised by malicious users. | |
| Modificada | Media (6.5) | 0.39% | — | EMC Avamar Server | 21/9/2016 | 17/6/2026 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program. | |
| Modificada | Alta (7.8) | 0.41% | — | EMC Avamar Server | 21/9/2016 | 17/6/2026 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration. | |
| Modificada | Media (6.7) | 0.43% | — | EMC Avamar Server | 21/9/2016 | 17/6/2026 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command. | |
| Modificada | Alta (8.6) | 1.4% | — | EMC Avamar Server | 21/9/2016 | 17/6/2026 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging… | |
| Modificada | Crítica (9.1) | 3.4% | — | EMC Avamar Server | 21/9/2016 | 17/6/2026 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent. | |
| Modificada | Alta (8.8) | 1.6% | — | EMC Avamar | 6/7/2016 | 17/6/2026 | The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation. | |
| Modificada | Alta (7.8) | 2.7% | — | EMC Avamar ServerEMC Avamar Server Virtual Edition | 23/7/2015 | 17/6/2026 | Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters. | |
| Modificada | Media (5) | 3.3% | — | Avamar Virtual Edition 6.0Avamar Virtual Edition 6.0.402Avamar Virtual Edition 7.0Avamar Virtual Edition 7.0.2-43 | 25/10/2014 | 17/6/2026 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call. | |
| Modificada | Media (4.3) | 1.6% | — | EMC Avamar | 25/10/2014 | 17/6/2026 | EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | |
| Modificada | Media (4.3) | 0.81% | — | EMC Avamar ServerEMC Avamar Server Virtual Edition | 19/7/2013 | 16/6/2026 | EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities." | |
| Modificada | Alta (9) | 3.1% | — | EMC Avamar ServerEMC Avamar Server Virtual Edition | 19/7/2013 | 16/6/2026 | EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 0.86% | — | EMC Avamar | 3/5/2013 | 16/6/2026 | EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Baja (3.5) | 0.86% | — | EMC Avamar | 3/5/2013 | 16/6/2026 | The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL. | |
| Modificada | Alta (7.2) | 0.34% | — | EMC AvamarEMC Avamar Plugin | 21/1/2013 | 16/6/2026 | EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack. | |
| Modificada | Baja (3.3) | 0.62% | — | EMC Avamar | 31/10/2012 | 16/6/2026 | EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to the proxy client. | |
| Modificada | Alta (7.7) | 1.1% | — | EMC Avamar | 19/9/2011 | 16/6/2026 | EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain. | |
| Modificada | Alta (8.5) | 2.5% | — | EMC Avamar | 16/3/2011 | 16/6/2026 | Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Avamar | 16/3/2011 | 16/6/2026 | The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to obtain sensitive information by sniffing the network. |