Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.20% | — | Dell Data Protection Central | 27/9/2023 | 17/6/2026 | Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext. | |
| Modificada | Media (6.5) | 0.94% | — | Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services | 6/6/2023 | 17/6/2026 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,… | |
| Modificada | Media (6.1) | 0.47% | — | Dell EMC Data Protection CentralDell Dp4400 FirmwareDell Dp5900 Firmware | 1/2/2023 | 17/6/2026 | Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections. | |
| Modificada | Media (5.4) | 0.43% | — | Dell EMC Data Protection Advisor | 30/8/2022 | 17/6/2026 | Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their… | |
| Modificada | Alta (8.8) | 0.36% | — | Dell EMC Data Protection Central | 21/7/2022 | 17/6/2026 | Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations. | |
| Modificada | Alta (7.5) | 1.2% | — | Dell EMC Data Protection Central | 24/1/2022 | 17/6/2026 | Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (4.3) | 0.55% | — | Dell EMC Data Protection Central | 24/1/2022 | 17/6/2026 | Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts. | |
| Modificada | Media (6.7) | 0.22% | — | Dell EMC Avamar ServerDell EMC Powerprotect Data Protection Appliance | 21/12/2021 | 17/6/2026 | Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application… | |
| Modificada | Alta (7.8) | 0.24% | — | Dell EMC Data Protection SearchDell EMC Integrated Data Protection Appliance | 10/8/2021 | 17/6/2026 | Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Modificada | Alta (7.5) | 1.1% | — | Dell EMC Data Protection Advisor | 28/7/2021 | 17/6/2026 | Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges. | |
| Modificada | Crítica (9.8) | 4.3% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance Firmware | 28/7/2021 | 17/6/2026 | Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization of Untrusted Data Vulnerability. A remote unauthenticated attacker could… | |
| Modificada | Alta (8.2) | 0.98% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 16/7/2021 | 17/6/2026 | Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause… | |
| Modificada | Alta (8.1) | 1.0% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 15/2/2021 | 17/6/2026 | Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain unauthorized read or modification access to other users' backup data. | |
| Modificada | Crítica (10) | 6.2% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This… | |
| Modificada | Alta (8.7) | 1.7% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary files. | |
| Modificada | Crítica (9.8) | 2.6% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 14/1/2021 | 17/6/2026 | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write… | |
| Modificada | Alta (8.8) | 2.9% | — | Dell EMC Data Protection Advisor | 6/7/2020 | 17/6/2026 | Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system. | |
| Modificada | Alta (7.2) | 2.0% | — | Dell EMC Integrated Data Protection Appliance | 15/4/2020 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of… | |
| Modificada | Alta (7.5) | 0.65% | — | Dell EMC Data Protection CentralDell EMC Integrated Data Protection Appliance | 18/3/2020 | 17/6/2026 | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise… | |
| Modificada | Alta (7.2) | 4.6% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance Firmware | 18/3/2020 | 17/6/2026 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject… | |
| Modificada | Alta (7.2) | 3.9% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance Firmware | 18/3/2020 | 17/6/2026 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter… | |
| Modificada | Alta (8.1) | 1.1% | — | Dell EMC Avamar ServerDell EMC Integrated Data Protection Appliance | 9/10/2019 | 17/6/2026 | Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4 contain an Incorrect Permission Assignment for Critical Resource vulnerability. A remote authenticated malicious user potentially could exploit this… | |
| Modificada | Media (4.8) | 0.78% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through… | |
| Modificada | Alta (8.8) | 2.1% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system. | |
| Modificada | Alta (7.2) | 0.70% | — | Dell EMC Integrated Data Protection Appliance Firmware | 27/9/2019 | 17/6/2026 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other… |