Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2772▲ 13 respecto a la semana anterior
Críticas / altas1288▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1981 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.12% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems. | |
| Modificada | Alta (7.3) | 0.18% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Media (4.3) | 0.23% | — | Dell Networker | 30/5/2023 | 17/6/2026 | Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates. | |
| Modificada | Alta (7.8) | 0.70% | — | Dell Vxrail Hyperconverged Infrastructure | 23/5/2023 | 17/6/2026 | Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable… | |
| Modificada | Alta (8.2) | 0.36% | — | Dell Vxrail Hyperconverged Infrastructure | 23/5/2023 | 17/6/2026 | Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Poweredge R740 FirmwareDell Poweredge R740xd FirmwareDell Poweredge R640 FirmwareDell Poweredge R940 Firmware+26 | 22/5/2023 | 17/6/2026 | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading… | |
| Modificada | Alta (7.1) | 0.18% | — | Dell Aiops Collector | 19/5/2023 | 7/8/2026 | Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data. | |
| Modificada | Alta (7.5) | 0.42% | — | Dell Cloudlink | 16/5/2023 | 17/6/2026 | CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Command | Monitor | 5/5/2023 | 17/6/2026 | Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected directory when Dell Command Monitor is installed to a non-default path | |
| Modificada | Alta (7.5) | 0.27% | — | Dell Elastic Cloud Storage | 4/5/2023 | 17/6/2026 | DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request. | |
| Modificada | Alta (7.8) | 0.14% | — | Dell Alienware Command Center | 3/5/2023 | 17/6/2026 | Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A local malicious user could potentially exploit this vulnerability during installation or update process leading to privilege escalation. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Display Manager | 20/4/2023 | 17/6/2026 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with high privileges. | |
| Modificada | Alta (8.8) | 0.77% | — | Dell Powerprotect Data Manager | 11/4/2023 | 17/6/2026 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Power Manager | 7/4/2023 | 17/6/2026 | Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system. | |
| Modificada | Alta (7.1) | 0.14% | — | Dell Display Manager | 6/4/2023 | 17/6/2026 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local low privilege attacker could potentially exploit this vulnerability, leading to the deletion of arbitrary files on the operating system with high privileges. | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Trusted Device Agent | 6/4/2023 | 17/6/2026 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | |
| Modificada | Media (5.4) | 0.43% | — | Dell Streaming Data Platform | 5/4/2023 | 17/6/2026 | Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks. | |
| Modificada | Media (6.5) | 0.60% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees. | |
| Modificada | Alta (7.4) | 0.29% | — | Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 17/3/2023 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a… | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. |