Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.49% | — | NSA Ghidra | 16/10/2019 | 17/6/2026 | NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory. | |
| Modificada | Alta (7.8) | 0.43% | — | NSA Ghidra | 16/10/2019 | 17/6/2026 | NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the "Ghidra Codebrowser > Window > Python" option, Ghidra will try to execute the cmd.exe program from this… | |
| Modificada | Crítica (9.8) | 5.1% | 💥 PoC | NSA Ghidra | 28/9/2019 | 17/6/2026 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with… | |
| Modificada | Crítica (9.1) | 2.4% | — | NSA Ghidra | 17/7/2019 | 17/6/2026 | NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file. | |
| Modificada | Alta (7.8) | 5.0% | 💥 Exploit | NSA Ghidra | 17/7/2019 | 17/6/2026 | In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for… | |
| Modificada | Crítica (9.8) | 3.3% | — | Dell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted input data to the WS-MAN interface. | |
| Modificada | Crítica (9.8) | 3.3% | — | Dell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface. | |
| Modificada | Crítica (9.8) | 4.2% | — | Dell Idrac6 FirmwareDell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 26/4/2019 | 17/6/2026 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or… | |
| Modificada | Media (6.8) | 0.42% | — | Dell Idrac7 FirmwareDell Idrac8 Firmware | 13/12/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell. | |
| Modificada | Alta (8.8) | 0.94% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 13/12/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to… | |
| Modificada | Media (5.9) | 0.89% | — | Dell Idrac9 Firmware | 2/7/2018 | 17/6/2026 | Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server. | |
| Modificada | Alta (8.8) | 3.4% | — | Dell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 2/7/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC… | |
| Modificada | Alta (7.5) | 1.8% | — | Dell Idrac6 FirmwareDell Idrac7 FirmwareDell Idrac8 FirmwareDell Idrac9 Firmware | 2/7/2018 | 17/6/2026 | Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce… | |
| Modificada | Alta (8.8) | 4.3% | — | Dell Idrac6 ModularDell Idrac6 Monolithic | 2/7/2018 | 17/6/2026 | The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as… | |
| Modificada | Media (6.5) | 0.45% | — | Dell EMC Idrac Service Module | 26/6/2018 | 17/6/2026 | Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host… | |
| Modificada | Alta (7.5) | 3.2% | — | Dell EMC Idrac7Dell EMC Idrac8 | 23/3/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Dell EMC Idrac7Dell EMC Idrac8 | 23/3/2018 | 17/6/2026 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code. | |
| Modificada | Alta (8.8) | 1.8% | — | Dell Idrac7 FirmwareDell Idrac8 Firmware | 29/11/2016 | 17/6/2026 | Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic | 19/12/2014 | 17/6/2026 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack. | |
| Modificada | Media (4.3) | 1.6% | — | Dell Idrac6 FirmwareDell Idrac6 MonolithicDell Idrac7 FirmwareDell Idrac7 | 24/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter. | |
| Modificada | Alta (10) | 3.6% | — | Dell Idrac6 Firmware | 8/7/2013 | 16/6/2026 | The web interface on the Dell iDRAC6 with firmware before 1.95 allows remote attackers to modify the CLP interface for arbitrary users and possibly have other impact via a request to an unspecified form that is accessible from testurls.html. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are… | |
| Modificada | Alta (10) | 3.4% | — | Dell Idrac6 BMC | 8/7/2013 | 16/6/2026 | The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of… | |
| Modificada | Baja (3.7) | 3.7% | 💥 Exploit | Fidra Lighthouse CMSAI | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology.… |