Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.84% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. | |
| Modificada | Alta (7.5) | 0.28% | — | Unisys Stealth | 3/2/2020 | 17/6/2026 | In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0. | |
| Modificada | Media (5.4) | 0.67% | — | Dell EMC PowermaxDell EMC Unisphere FOR Powermax | 10/1/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject… | |
| Modificada | Alta (8.7) | 0.79% | — | Unisys MCP Firmware | 7/1/2020 | 17/6/2026 | Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving specifically crafted message payloads over a systems management communication channel | |
| Modificada | Alta (8.8) | 4.1% | — | Crosscert Unisign | 13/8/2019 | 17/6/2026 | UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack with arbitrary data, due to a buffer overflow in a library. That leads remote attacker to execute arbitrary code via crafted https packets. | |
| Modificada | Media (4.7) | 0.16% | — | Unisys Stealth Authorization Server | 30/5/2018 | 17/6/2026 | In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory. | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… | |
| Modificada | Alta (7.5) | 1.5% | — | Unisys Stealth SVG | 3/4/2018 | 17/6/2026 | The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux and AIX, allows remote attackers to cause a denial of service (crash) via crafted packets. | |
| Modificada | Alta (8.1) | 0.93% | — | Unisys Clearpath Eportal ManagerUnisys Eportal-2200 | 26/3/2018 | 17/6/2026 | SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters. | |
| Modificada | Crítica (9.8) | 21% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Alta (8.8) | 4.2% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Media (5.9) | 1.0% | — | Unisys Clearpath MCP | 26/2/2018 | 17/6/2026 | The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160, 59.1 before 059.1a.17 (IC #17), and 60.0 before 60.044 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Alta (7.8) | 0.29% | — | Unisys Stealth | 19/2/2018 | 17/6/2026 | Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of memory used for negotiation key storage. | |
| Modificada | Crítica (9.8) | 4.8% | — | Dell EMC UnisphereEMC Solutions EnablerEMC VasaEMC Vmax Emanagement | 1/11/2017 | 17/6/2026 | EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125… | |
| Modificada | Alta (7.8) | 0.41% | — | Unisys Mcp-firmware | 30/9/2017 | 17/6/2026 | Unisys Libra 64xx and 84xx and FS601 class systems with MCP-FIRMWARE before 43.211 allow remote authenticated users to cause a denial of service (program crash) or have unspecified other impact via vectors related to incorrect literal handling, which trigger CPM stack corruption. | |
| Modificada | Media (5.9) | 0.64% | — | Unisys Mobigate | 9/6/2017 | 17/6/2026 | The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.7) | 0.41% | — | Unisys Secure Partitioning | 11/4/2017 | 17/6/2026 | Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. | |
| Modificada | Alta (7.5) | 1.5% | — | Unisys Clearpath MCP | 10/3/2017 | 17/6/2026 | The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows remote attackers to cause a denial of service (network connectivity disruption) via a client hello with a signature_algorithms extension… | |
| Modificada | Media (6.8) | 0.92% | — | Unisys Mcp-firmware | 3/2/2017 | 17/6/2026 | Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow remote authenticated users to cause a denial of service (data corruption or system crash) via vectors related to using program operators during EPSILON (level 5) based codefiles at peak memory usage,… | |
| Modificada | Crítica (9.8) | 4.9% | — | Dell EMC UnisphereEMC Solutions EnablerEMC Unisphere | 5/10/2016 | 17/6/2026 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class. | |
| Modificada | Alta (8.8) | 3.6% | — | Dell EMC UnisphereEMC Solutions EnablerEMC Unisphere | 5/10/2016 | 17/6/2026 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest… | |
| Modificada | Crítica (9.8) | 3.1% | — | Dell EMC Unisphere | 15/4/2016 | 17/6/2026 | An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a crafted pathname. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Precision Thunis-800+ | 4/8/2015 | 17/6/2026 | GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2) TH8740 for installation using TH8740_122_Setup.exe, (3) hrml for "Setup and Activation" using DSASetup, and (4) an empty string for Shutter Configuration, which has unspecified impact and attack… | |
| Modificada | Alta (10) | 4.5% | — | EMC Unisphere | 29/6/2015 | 17/6/2026 | EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.8) | 1.8% | — | EMC Unisphere Central | 2/2/2015 | 17/6/2026 | Open redirect vulnerability in EMC Unisphere Central before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter. |