Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 6.5% | — | Lifesize Team 220 FirmwareLifesize Passport 220 FirmwareLifesize Networker 220 FirmwareLifesize Room 220 Firmware | 8/2/2019 | 17/6/2026 | LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication. | |
| Modificada | Alta (8.8) | 0.68% | — | Dell EMC Networker | 1/8/2018 | 17/6/2026 | Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote AMQP service. An unauthenticated attacker… | |
| Modificada | Alta (7.5) | 16% | — | Dell EMC Networker | 19/3/2018 | 17/6/2026 | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages. A remote unauthenticated attacker could potentially exploit this vulnerability to cause a denial of service to the… | |
| Modificada | Alta (8.8) | 8.2% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of… | |
| Modificada | Alta (8.8) | 5.5% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any… | |
| Modificada | Crítica (9.8) | 4.7% | — | EMC Avamar ServerEMC Integrated Data Protection ApplianceEMC Networker | 5/1/2018 | 17/6/2026 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the… | |
| Modificada | Alta (8.1) | 3.2% | — | EMC Networker | 18/10/2017 | 17/6/2026 | An issue was discovered in EMC NetWorker (prior to 8.2.4.9, all supported 9.0.x versions, prior to 9.1.1.3, prior to 9.2.0.4). The Server service (nsrd) is affected by a buffer overflow vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on vulnerable… | |
| Modificada | Crítica (9.8) | 2.6% | — | EMC Networker Module FOR Microsoft ApplicationsEMC Replication Manager | 5/10/2016 | 17/6/2026 | The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsoft 8.2.x before 8.2.3.6 allows remote RM servers to execute arbitrary commands by placing a crafted script in an SMB share. | |
| Modificada | Crítica (9.8) | 7.7% | — | EMC Networker | 10/6/2016 | 17/6/2026 | EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance. | |
| Modificada | Alta (7.8) | 2.3% | — | EMC Networker | 5/12/2015 | 17/6/2026 | EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of service (process outage) via malformed RPC authentication messages. | |
| Modificada | Alta (7.2) | 0.40% | — | EMC Networker | 17/4/2015 | 17/6/2026 | Buffer overflow in an unspecified function in nsr_render_log in EMC NetWorker before 8.0.4.3, 8.1.x before 8.1.2.6, and 8.2.x before 8.2.1.2 allows local users to gain privileges via unknown vectors. | |
| Modificada | Baja (2.1) | 0.53% | — | MeditechEMC Networker | 25/10/2014 | 17/6/2026 | The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files. | |
| Modificada | Baja (3.5) | 1.00% | — | EMC Networker | 2/11/2013 | 16/6/2026 | The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources. | |
| Modificada | Media (4.6) | 0.30% | — | EMC Networker | 31/7/2013 | 16/6/2026 | EMC NetWorker 7.6.x and 8.x before 8.1 allows local users to obtain sensitive configuration information by leveraging operating-system privileges to perform decryption with nsradmin. | |
| Modificada | Alta (7.2) | 0.39% | — | EMC Networker | 3/5/2013 | 16/6/2026 | The nsrpush process in the client in EMC NetWorker before 7.6.5.3 and 8.x before 8.0.1.4 sets weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (9.3) | 3.2% | — | EMC Networker | 17/1/2013 | 16/6/2026 | Buffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code via crafted SunRPC data. | |
| Modificada | Alta (9.3) | 3.6% | — | EMC Networker Module FOR Microsoft Applications | 18/10/2012 | 16/6/2026 | The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel. | |
| Modificada | Baja (2.1) | 0.33% | — | EMC Networker Module FOR Microsoft Applications | 18/10/2012 | 16/6/2026 | The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors. | |
| Modificada | Alta (9.3) | 33% | — | EMC Networker | 4/9/2012 | 16/6/2026 | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message. | |
| Modificada | Alta (9.3) | 3.0% | — | EMC Networker | 27/1/2012 | 16/6/2026 | Buffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.9) | 0.31% | — | EMC Networker | 22/4/2011 | 16/6/2026 | EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (10) | 64% | — | EMC Replication ManagerEMC Networker Module | 10/2/2011 | 16/6/2026 | The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542. | |
| Modificada | Media (6.4) | 2.6% | — | EMC Networker | 1/2/2011 | 16/6/2026 | librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or… | |
| Modificada | Alta (10) | 40% | — | IBM Informix Dynamic ServerEMC Legato Networker | 5/3/2010 | 16/6/2026 | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code… | |
| Modificada | Alta (7.8) | 2.9% | — | EMC Networker ClientEMC Networker ModuleEMC Networker PowersnapEMC Networker Server+1 | 20/2/2009 | 16/6/2026 | nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0… |