Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 29/5/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in… | |
| Modificada | Crítica (9.8) | 42% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 29/5/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege. | |
| Modificada | Media (6.7) | 6.3% | — | Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines | 3/2/2018 | 17/6/2026 | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape from the restricted shell to an interactive… | |
| Modificada | Media (6.7) | 1.1% | — | Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines | 3/2/2018 | 17/6/2026 | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Boxmgmt CLI may allow a malicious user with boxmgmt privileges to bypass Boxmgmt CLI and run arbitrary commands… | |
| Modificada | Alta (8.2) | 1.7% | — | Ethereum Virtual Machine | 19/1/2018 | 17/6/2026 | An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An attacker can create/send malicious a… | |
| Modificada | Media (5.6) | 94% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Alta (7.5) | 1.6% | — | Dell Recoverpoint FOR Virtual MachinesEMC Recoverpoint | 21/3/2017 | 10/7/2026 | EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (6.7) | 0.89% | — | Dell Recoverpoint FOR Virtual MachinesEMC Recoverpoint | 3/2/2017 | 10/7/2026 | EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root. | |
| Modificada | Media (4.4) | 0.43% | — | Dell Recoverpoint FOR Virtual MachinesEMC Recoverpoint | 3/2/2017 | 10/7/2026 | EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive… | |
| Modificada | Crítica (9.8) | 3.9% | — | Teradata Virtual Machine | 10/11/2016 | 17/6/2026 | Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to elevated code execution. | |
| Modificada | Alta (7.8) | 0.51% | — | Teradata Virtual Machine | 10/11/2016 | 17/6/2026 | Teradata Virtual Machine Community Edition v15.10 has insecure file permissions on /etc/luminex/pkgmgr. These could allow a local user to modify its contents and execute commands as root. | |
| Modificada | Media (4.3) | 4.7% | — | PHPHiphop Virtual Machine FOR PHP Project Hiphop Virtual Machine FOR PHP | 22/5/2016 | 17/6/2026 | Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive. | |
| Modificada | Alta (7.2) | 0.40% | — | EMC Recoverpoint FOR Virtual Machines | 10/7/2015 | 17/6/2026 | EMC RecoverPoint for Virtual Machines (VMs) 4.2 allows local users to obtain root-shell access by bypassing the Installation Manager Boxmgmt CLI interface. | |
| Modificada | Media (4.3) | 2.1% | — | Facebook Hiphop Virtual Machine | 13/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function. | |
| Modificada | Media (6.9) | 1.6% | — | Microsoft Virtual Machine Manager | 11/2/2015 | 17/6/2026 | Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Directory credentials, aka "Virtual Machine Manager Elevation… | |
| Modificada | Media (5) | 1.7% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by leveraging read access beyond the end of the string, and makes it… | |
| Modificada | Alta (7.5) | 1.9% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split function. | |
| Modificada | Media (5) | 1.5% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initialization vector. | |
| Modificada | Media (5) | 2.1% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory. | |
| Modificada | Alta (7.5) | 2.7% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string. | |
| Modificada | Media (5) | 1.5% | — | Hiphop Virtual Machine FOR PHP Project Hiphop Virtual Machine FOR PHP | 5/2/2014 | 17/6/2026 | The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a certain libxml handler, which allows remote attackers to conduct XML External Entity (XXE) attacks. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Control Virtual Machine Management | 28/10/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5) | 2.4% | — | HP Insight Control Virtual Machine Management | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to bypass intended access restrictions and cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 1.5% | — | HP Insight Control Virtual Machine Management | 28/10/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9) | 4.7% | — | HP Insight Virtual Machine Management | 23/4/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Virtual Machine Manager (VMM) before 6.0 allow remote authenticated users to execute arbitrary code via unknown vectors. |