Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.49% | — | Dell Idrac8 Firmware | 18/1/2023 | 17/6/2026 | Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. | |
| Modificada | Media (4.9) | 0.51% | — | Dell Idrac9 Firmware | 18/1/2023 | 17/6/2026 | Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. | |
| Modificada | Crítica (9.8) | 2.9% | — | NSA Ghidra | 6/1/2023 | 17/6/2026 | Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input. | |
| Modificada | Crítica (9.8) | 59% | — | Dell Idrac9 | 26/5/2022 | 17/6/2026 | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. | |
| Modificada | Alta (7.2) | 28% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system. | |
| Modificada | Alta (8.2) | 33% | — | Dell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure. | |
| Modificada | Alta (8.1) | 30% | — | Dell EMC Idrac9 Firmware | 23/11/2021 | 17/6/2026 | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data… | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Media (4.3) | 0.69% | — | Dell EMC Idrac8 FirmwareDell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate. | |
| Modificada | Media (6.1) | 0.81% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. | |
| Modificada | Media (6.1) | 0.81% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Media (6.1) | 0.75% | — | Dell EMC Idrac9 Firmware | 3/8/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link. | |
| Modificada | Crítica (10) | 1.7% | — | Dell Idrac9 Firmware | 29/7/2021 | 17/6/2026 | Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console. | |
| Modificada | Baja (2.7) | 0.92% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user. | |
| Modificada | Media (4.8) | 0.63% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access… | |
| Modificada | Media (4.8) | 0.40% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.10.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected while generating a certificate. When… | |
| Modificada | Media (6.1) | 0.81% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a DOM-based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is… | |
| Modificada | Alta (8.1) | 1.2% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to overwrite configuration information by injecting arbitrarily large payload. | |
| Modificada | Alta (7.1) | 0.62% | — | Dell Idrac9 Firmware | 30/4/2021 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface. | |
| Modificada | Media (6.1) | 1.0% | — | Dell Idrac8 Firmware | 8/3/2021 | 17/6/2026 | Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections. | |
| Modificada | Media (6.1) | 1.0% | — | Dell Idrac9 Firmware | 16/12/2020 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially… | |
| Modificada | Media (6.5) | 1.8% | — | Dell Idrac9 Firmware | 9/7/2020 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files. | |
| Modificada | Crítica (9.8) | 3.8% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 31/3/2020 | 17/6/2026 | Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data. | |
| Modificada | Media (4.3) | 0.88% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 7/11/2019 | 17/6/2026 | Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as… |