Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

25.884 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.45%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaMedia (6.4)0.23%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
AnalizadaAlta (8.1)0.38%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
AnalizadaMedia (5.4)0.21%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaAlta (7.5)0.53%—Dell Openmanage Server Administrator17/9/20262/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaAlta (7.2)0.62%—Dell Openmanage Server Administrator17/9/20262/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaMedia (5.5)0.17%—Dell Openmanage Server Administrator17/9/20262/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaCrítica (9.8)0.29%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaAlta (7.2)0.62%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaCrítica (9.8)0.95%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaCrítica (9.8)0.53%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (5.5)0.11%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaCrítica (9.8)0.21%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaAlta (7.8)0.15%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (6.5)0.17%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AnalizadaAlta (7.5)0.15%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.5)0.20%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AplazadaAlta (7.6)0.42%—Decap-serverAI16/9/202622/9/2026
decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended…
AplazadaAlta (7.1)0.46%—SecobserveAI16/9/202624/9/2026
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service…
Pendiente de análisisCrítica (10)0.56%—Altium Enterprise ServerAI16/9/202618/9/2026
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server…
Pendiente de análisisMedia (4.2)0.11%—Jenkins Bitbucket Server Integration PluginAI16/9/202618/9/2026
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
Pendiente de análisisAlta (8.7)0.69%—Octopus ServerAI16/9/202616/9/2026
In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
Pendiente de análisisCrítica (9.5)0.28%—Secret ServerAI15/9/202618/9/2026
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Pendiente de análisisCrítica (9.1)0.20%—Delinea Secret ServerAI15/9/202618/9/2026
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
Pendiente de análisisAlta (8.1)0.37%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…