Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Checkpoint Capsule Docs Standalone ClientCheckpoint Endpoint SecurityCheckpoint Remote Access Clients | 29/8/2019 | 17/6/2026 | Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+2 | 20/6/2019 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one. | |
| Modificada | Media (4.4) | 0.97% | — | Checkpoint Endpoint Security ClientsCheckpoint Remote Access ClientsCheckpoint Capsule Docs | 20/6/2019 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary,… | |
| Modificada | Media (6.1) | 1.2% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. | |
| Modificada | Alta (8.8) | 2.0% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. | |
| Modificada | Crítica (9.8) | 2.7% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input. | |
| Modificada | Crítica (9.8) | 2.7% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal. | |
| Modificada | Crítica (9.8) | 7.1% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application… | |
| Modificada | Crítica (9.8) | 12% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal… | |
| Modificada | Crítica (9.8) | 23% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system.… | |
| Modificada | Media (6.8) | 3.9% | — | Sonicwall Remote Access Firmware | 1/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to… | |
| Modificada | Media (6.9) | 0.40% | — | Checkpoint Endpoint ConnectCheckpoint Endpoint SecurityCheckpoint Endpoint Security VPNCheckpoint Remote Access Clients | 19/6/2012 | 16/6/2026 | Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the… | |
| Modificada | Media (4.3) | 1.5% | — | Dell Remote Access Card | 15/8/2007 | 16/6/2026 | Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to cause a denial of service (SSH daemon crash) via certain network traffic, as demonstrated by an "nmap -O" scan with nmap 4.03, possibly related to a Mocana (Mocanada) SSH vulnerability. |