Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.11%—NSA Ghidra10/6/202614/7/2026
Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe…
Pendiente de análisisMedia (6)0.13%—Dell Idrac ToolsAI9/6/202623/7/2026
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
AplazadaMedia (4.4)0.13%—HidrawAI26/5/202624/7/2026
A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could…
AnalizadaAlta (7.1)0.27%—Dell Idrac10 Firmware29/4/202617/6/2026
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.
AnalizadaAlta (8.8)0.77%—NSA Ghidra29/3/202610/8/2026
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in…
AplazadaAlta (7.8)0.10%—Dell Idrac Service ModuleAIDell Idrac Service Module FOR WindowsAIDell Idrac Service Module FOR LinuxAI12/2/202617/6/2026
Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…
AnalizadaMedia (4.9)0.43%—Dell Idrac9 FirmwareDell Idrac10 Firmware6/11/202517/6/2026
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')…
AnalizadaMedia (4.9)0.31%—Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+10825/9/202517/6/2026
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (7.8)0.15%—Dell EMC Idrac Service Module21/8/202517/6/2026
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.
AnalizadaMedia (5.3)0.12%—Dell EMC Idrac Service Module21/8/202517/6/2026
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaAlta (7.8)0.13%—Dell Idrac Tools12/6/202517/6/2026
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaCrítica (9.1)0.72%💥 PoCAidraw I DrawAI17/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.
AplazadaAlta (8)0.30%—Atos Eviden IdraAI18/2/202517/6/2026
An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges.
AplazadaMedia (6.8)0.36%—Atos Eviden IdraAIAtos Eviden IdcaAI18/2/202517/6/2026
Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confidential data. Data integrity and availability is not at risk.
AplazadaCrítica (9.9)0.41%—Atos Eviden IdraAI18/2/202517/6/2026
Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.
AnalizadaMedia (4.4)0.16%—Dell EMC Idrac Service Module1/8/202417/6/2026
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
AnalizadaMedia (4.4)0.20%—Dell EMC Idrac Service Module1/8/202417/6/2026
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.
AnalizadaMedia (4.4)0.16%—Dell EMC Idrac Service Module1/8/202417/6/2026
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
AnalizadaMedia (4.4)0.16%—Dell EMC Idrac Service Module1/8/202417/6/2026
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
AnalizadaMedia (4.4)0.16%—Dell EMC Idrac Service Module1/8/202417/6/2026
Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
AnalizadaCrítica (9.8)0.66%—Dell Idrac929/6/202417/6/2026
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.
AplazadaMedia (6.1)0.56%—ExcalidrawAI17/4/202417/6/2026
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without…
AnalizadaAlta (8)0.83%—Dell Idrac89/3/202417/6/2026
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
ModificadaAlta (7.8)0.17%—Dell EMC Idrac Service Module16/1/202417/6/2026
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
ModificadaMedia (6.1)0.56%—Excalidraw16/8/202317/6/2026
Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
Orbitaley — Vulnerabilidades