Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.25%—EMC Elan Match-on-chip FPR Solution Firmware12/1/202417/6/2026
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS)…
ModificadaAlta (7.5)0.61%—Sem-cms Semcms10/1/202417/6/2026
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
ModificadaMedia (5.3)0.40%—Dell EMC Networker18/12/202317/6/2026
Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to some information disclosure.
ModificadaAlta (7.2)1.8%—Dell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management CenterDell EMC Data Domain OS+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying…
ModificadaMedia (6.1)0.76%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM…
ModificadaAlta (7.8)0.22%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
ModificadaMedia (4.3)0.57%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized…
ModificadaMedia (6.7)0.62%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by…
ModificadaMedia (6.7)0.29%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the…
ModificadaCrítica (9.8)0.63%—Sem-cms Semcms14/12/202317/6/2026
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
ModificadaAlta (7.8)0.60%—Dell Powerprotect Data ProtectionDell Apex Protection StorageDell Powerprotect Data DomainDell Powerprotect Data Domain Management Center+114/12/202317/6/2026
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with…
ModificadaAlta (7.8)0.19%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+1228/12/202317/6/2026
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
ModificadaAlta (7.5)0.86%—Sem-cms Semcms4/12/202317/6/2026
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter.…
ModificadaMedia (5.4)0.41%—Elijaa Phpmemcachedadmin30/11/202317/6/2026
A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the…
ModificadaCrítica (9.1)0.86%—Elijaa Phpmemcachedadmin30/11/202317/6/2026
A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.
ModificadaCrítica (9.8)0.76%—Memcached27/10/202317/6/2026
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
ModificadaAlta (7.5)0.78%—Memcached27/10/202317/6/2026
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
ModificadaAlta (7.8)0.16%—Dell EMC Openmanage Server Administrator13/10/202317/6/2026
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system…
ModificadaAlta (8.8)0.25%—Palasthotel USE Memcached9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel (in person: Edward Bock) Use Memcached plugin <= 1.0.4 versions.
ModificadaAlta (7.8)0.18%—EMC Appsync27/9/202317/6/2026
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege escalation.
ModificadaMedia (6.7)0.17%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+4815/9/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges.
ModificadaAlta (7.5)1.1%—Memcached22/8/202317/6/2026
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
ModificadaAlta (7.5)1.3%—Memcached22/8/202317/6/2026
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
ModificadaAlta (7.2)1.1%—Sem-cms Semcms5/8/202317/6/2026
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
ModificadaCrítica (9.8)0.62%—Sem-cms Semcms31/7/20239/7/2026
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Orbitaley — Vulnerabilidades