Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.23% | — | Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 13/2/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized. | |
| Modificada | Alta (8.8) | 1.4% | — | Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 11/2/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system. | |
| Modificada | Media (6.5) | 0.74% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell EMC Vasa Provider Virtual Appliance+4 | 18/1/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system. | |
| Modificada | Alta (8) | 0.33% | — | Dell Evasa Provider Virtual ApplianceDell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360+4 | 31/8/2022 | 17/6/2026 | Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+3 | 21/1/2022 | 17/6/2026 | The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance. | |
| Modificada | Alta (8) | 0.36% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+3 | 21/1/2022 | 17/6/2026 | Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338. | |
| Modificada | Alta (7.8) | 0.69% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance+1 | 30/4/2021 | 17/6/2026 | Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions. | |
| Modificada | Media (5.4) | 0.63% | — | Dell UnisphereDell Powermax OS | 5/1/2021 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject… | |
| Modificada | Alta (8.1) | 0.59% | — | Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 23/6/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a… | |
| Modificada | Media (5.4) | 0.75% | — | Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 23/6/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics. | |
| Modificada | Media (5.4) | 0.67% | — | Dell EMC PowermaxDell EMC Unisphere FOR Powermax | 10/1/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject… | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… | |
| Modificada | Crítica (9.8) | 21% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Alta (8.8) | 4.2% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Crítica (9.8) | 4.8% | — | Dell EMC UnisphereEMC Solutions EnablerEMC VasaEMC Vmax Emanagement | 1/11/2017 | 17/6/2026 | EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125… | |
| Modificada | Crítica (9.8) | 4.9% | — | Dell EMC UnisphereEMC Solutions EnablerEMC Unisphere | 5/10/2016 | 17/6/2026 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class. | |
| Modificada | Alta (8.8) | 3.6% | — | Dell EMC UnisphereEMC Solutions EnablerEMC Unisphere | 5/10/2016 | 17/6/2026 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest… | |
| Modificada | Crítica (9.8) | 3.1% | — | Dell EMC Unisphere | 15/4/2016 | 17/6/2026 | An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a crafted pathname. | |
| Modificada | Alta (10) | 4.5% | — | EMC Unisphere | 29/6/2015 | 17/6/2026 | EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.8) | 1.8% | — | EMC Unisphere Central | 2/2/2015 | 17/6/2026 | Open redirect vulnerability in EMC Unisphere Central before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter. | |
| Modificada | Baja (1.9) | 0.30% | — | Dell EMC Unisphere | 2/11/2013 | 16/6/2026 | EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console. |