Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.16% | — | Dell EMC Idrac Service Module | 1/8/2024 | 17/6/2026 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | |
| Analizada | Media (4.4) | 0.20% | — | Dell EMC Idrac Service Module | 1/8/2024 | 17/6/2026 | Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event. | |
| Analizada | Media (4.4) | 0.16% | — | Dell EMC Idrac Service Module | 1/8/2024 | 17/6/2026 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | |
| Analizada | Media (4.4) | 0.16% | — | Dell EMC Idrac Service Module | 1/8/2024 | 17/6/2026 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | |
| Analizada | Media (4.4) | 0.16% | — | Dell EMC Idrac Service Module | 1/8/2024 | 17/6/2026 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | |
| Analizada | Media (5.9) | 0.39% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php. | |
| Analizada | Alta (7.5) | 0.70% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php. | |
| Analizada | Media (6.5) | 0.57% | — | Sem-cms Semcms | 7/5/2024 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Aplazada | Media (4.3) | 0.53% | — | EMC EroomAI | 2/5/2024 | 17/6/2026 | The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft… | |
| Modificada | Alta (7.1) | 0.47% | — | Sem-cms Semcms | 19/4/2024 | 9/7/2026 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Analizada | Crítica (9.8) | 0.76% | — | Sem-cms Semcms | 19/4/2024 | 17/6/2026 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+89 | 3/4/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Analizada | Crítica (9.8) | 1.2% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file. | |
| Analizada | Alta (7.5) | 0.79% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php. | |
| Analizada | Media (6.5) | 0.74% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php. | |
| Analizada | Alta (7.2) | 0.80% | — | Sem-cms Semcms | 29/3/2024 | 17/6/2026 | SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges. | |
| Analizada | Alta (7.8) | 0.18% | — | Sagemcom F@st 3686 Firmware | 14/3/2024 | 17/6/2026 | Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details… | |
| Analizada | Baja (3.3) | 0.17% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analizada | Media (6.3) | 0.11% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. | |
| Analizada | Alta (8.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM. | |
| Analizada | Baja (3.3) | 0.20% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analizada | Alta (8.4) | 0.20% | — | Dell Poweredge T360 FirmwareDell Poweredge R360 FirmwareDell Poweredge R650 FirmwareDell Poweredge R750 Firmware+82 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Sem-cms Semcms | 28/2/2024 | 17/6/2026 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component. | |
| Modificada | Media (6.8) | 0.52% | — | Dell EMC Appsync | 8/2/2024 | 17/6/2026 | Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker… | |
| Modificada | Alta (7.8) | 0.17% | — | Dell EMC Idrac Service Module | 16/1/2024 | 17/6/2026 | Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity. |