Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | |
| Modificada | Alta (7.1) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | |
| Modificada | Alta (7.8) | 0.35% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | |
| Modificada | Media (6.8) | 0.30% | — | Dell Supportassist OS Recovery | 26/5/2022 | 17/6/2026 | Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator. | |
| Modificada | Alta (7.8) | 0.46% | — | Dell Supportassist FOR Home PCS | 28/9/2021 | 17/6/2026 | SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's, | |
| Modificada | Alta (7.1) | 0.26% | — | Dell Supportassist Client Consumer | 28/9/2021 | 17/6/2026 | Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by… | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 22/7/2021 | 17/6/2026 | Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path… | |
| Modificada | Alta (7.8) | 0.35% | — | Dell Supportassist Client PromanageDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 12/3/2021 | 17/6/2026 | Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially… | |
| Modificada | Alta (7.8) | 2.2% | — | Pc-doctor ToolboxDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/6/2019 | 17/6/2026 | PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. | |
| Modificada | Alta (7.8) | 0.26% | — | Dell Supportassist FOR Home PCSDell Supportassist FOR Business PCS | 20/6/2019 | 17/6/2026 | Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread… | |
| Modificada | Alta (8) | 16% | 💥 PoC | Dell Supportassist | 18/4/2019 | 17/6/2026 | Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via… | |
| Modificada | Alta (8.8) | 0.67% | — | Dell Supportassist | 18/4/2019 | 17/6/2026 | Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems. | |
| Modificada | Alta (7) | 0.76% | — | Dell EMC Supportassist Enterprise | 12/2/2018 | 17/6/2026 | Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with… |