Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Dell EMC Unity Operating Environment25/1/202217/6/2026
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
ModificadaAlta (7.8)0.24%—Dell EMC Unity Operating Environment25/1/202217/6/2026
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.
ModificadaMedia (5.5)0.20%—Dell EMC System Update24/1/202217/6/2026
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.
ModificadaMedia (6.7)0.44%—Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment24/1/202217/6/2026
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity…
ModificadaAlta (7.5)1.2%—Dell EMC Data Protection Central24/1/202217/6/2026
Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (4.3)0.55%—Dell EMC Data Protection Central24/1/202217/6/2026
Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.
ModificadaCrítica (9.8)1.1%—Dell EMC Appsync21/1/202217/6/2026
Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak…
ModificadaMedia (6.1)0.69%—Dell EMC Appsync21/1/202217/6/2026
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.
ModificadaAlta (8.8)0.39%—Dell EMC Appsync21/1/202217/6/2026
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
ModificadaMedia (6.7)0.23%—Dell EMC Avamar Server21/12/202117/6/2026
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
ModificadaMedia (6.7)0.22%—Dell EMC Avamar ServerDell EMC Powerprotect Data Protection Appliance21/12/202117/6/2026
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application…
ModificadaAlta (7.2)0.75%—Dell EMC Avamar Server21/12/202117/6/2026
Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with high privileges could potentially exploit this vulnerability, leading to the disclosure of the AUI info and performing some unauthorized operation on the AUI.
ModificadaAlta (7.5)1.1%—Sem-cms Semcms17/12/202117/6/2026
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
ModificadaCrítica (9.8)1.0%—Sem-cms Semcms17/12/202117/6/2026
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
ModificadaCrítica (9.8)1.2%—Dell EMC Streaming Data Platform30/11/202117/6/2026
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.
ModificadaMedia (6.5)0.70%—Dell EMC Streaming Data Platform30/11/202117/6/2026
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.
ModificadaAlta (8.8)0.87%—Dell EMC Streaming Data Platform30/11/202117/6/2026
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.
ModificadaMedia (5.3)1.0%—Dell EMC Streaming Data Platform30/11/202117/6/2026
Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of the attacker's choice.
ModificadaMedia (6.5)1.2%—Dell EMC Streaming Data Platform30/11/202117/6/2026
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.
ModificadaAlta (8.8)1.2%—Dell EMC Cloud Link23/11/202117/6/2026
Dell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, leading to execution of arbitrary files on the server
ModificadaMedia (6.8)0.73%—Dell EMC Cloud Link23/11/202117/6/2026
Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to arbitrary code execution on end user machine
ModificadaMedia (5.5)0.21%—Dell EMC Cloud Link23/11/202117/6/2026
Dell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially exploit this vulnerability, leading to an application crash.
ModificadaMedia (5.4)0.58%—Dell EMC Cloud Link23/11/202117/6/2026
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.
ModificadaCrítica (9.8)1.2%—Dell EMC Cloud Link23/11/202117/6/2026
Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.
ModificadaAlta (7.8)0.20%—Dell EMC Networker23/11/202117/6/2026
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized locations and execute it.
Orbitaley — Vulnerabilidades