Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.46% | — | Dell Powerprotect Data Manager | 10/9/2025 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Powerprotect Data Manager | 10/9/2025 | 17/6/2026 | Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (6.5) | 0.35% | — | Dell Powerprotect Data Manager | 30/7/2025 | 17/6/2026 | Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. | |
| Analizada | Baja (3.4) | 0.15% | — | Dell Powerprotect Data Manager | 28/4/2025 | 17/6/2026 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs. | |
| Analizada | Media (4.4) | 0.17% | — | Dell Powerprotect Data Manager | 28/4/2025 | 17/6/2026 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Powerprotect Data Manager | 28/4/2025 | 17/6/2026 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.9) | 0.38% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the… | |
| Analizada | Media (6.9) | 0.21% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change arbitrary device settings by tricking a legitimate device administrator to… | |
| Analizada | Crítica (10) | 0.62% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access to the device operating system with root privileges. This could allow unauthenticated remote attackers to gain full access to a device, if they are in possession of… | |
| Analizada | Alta (7.7) | 0.54% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint that allows to enable the ssh service without authentication. This could allow an unauthenticated remote attacker to enable remote access to the device via ssh. | |
| Analizada | Crítica (9.2) | 0.57% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path traversal vulnerability. This could allow an unauthenticated attacker it to access arbitrary files on the device with root privileges. | |
| Analizada | Media (6.9) | 0.38% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate report creation requests. This could allow an unauthenticated remote attacker to read or clear the log files on the device, reset the device or set the date and time. | |
| Analizada | Crítica (9.4) | 0.89% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges. | |
| Analizada | Crítica (9.4) | 0.89% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges. | |
| Analizada | Crítica (9.4) | 0.89% | — | Siemens 7KT Pac1260 Data Manager Firmware | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges. | |
| Modificada | Alta (7.2) | 0.40% | — | Wpexpertplugins Post Meta Data Manager | 8/3/2025 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due to the plugin not properly verifying the existence of a multisite installation prior to allowing user meta to be added/modified. This makes it possible for… | |
| Modificada | Media (5.4) | 0.34% | — | Wpexpertplugins Post Meta Data Manager | 2/7/2024 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Media (6.5) | 0.56% | — | Dell Powerprotect Data Manager | 28/3/2024 | 17/6/2026 | Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service. | |
| Modificada | Alta (8.8) | 0.56% | — | Dell Powerprotect Data Manager | 13/2/2024 | 17/6/2026 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The… | |
| Modificada | Alta (7.2) | 1.4% | — | Dell Powerprotect Data Manager | 13/2/2024 | 17/6/2026 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell Powerprotect Data Manager Dm5500 Firmware | 4/12/2023 | 17/6/2026 | Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could possibly lead to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.48% | — | Dell Powerprotect Data Manager Dm5500 Firmware | 4/12/2023 | 17/6/2026 | Dell DM5500 5.14.0.0 and prior contain a Reflected Cross-Site Scripting Vulnerability. A network attacker with low privileges could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application.… | |
| Modificada | Media (5.5) | 0.19% | — | Dell Powerprotect Data Manager Dm5500 Firmware | 4/12/2023 | 17/6/2026 | Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be able to use the exposed credentials to access the vulnerable… | |
| Modificada | Alta (7.2) | 1.6% | — | Dell Powerprotect Data Manager Dm5500 Firmware | 4/12/2023 | 17/6/2026 | Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the vulnerable application. Exploitation may lead to… | |
| Modificada | Alta (8.8) | 0.29% | — | Wpexpertplugins Post Meta Data Manager | 21/11/2023 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions. This makes it possible for unauthenticated… |