Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.9) | 0.49% | — | Integrated Dell Remote Access Controller 9AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Integrated Dell Remote Access Controller 9AIIntegrated Dell Remote Access Controller 10AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could… | |
| Aplazada | Alta (8.5) | 0.18% | — | Program Access ControllerAI | 28/1/2026 | 17/6/2026 | Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Modificada | Alta (8.8) | 0.94% | — | Cassianetworks Access Controller | 27/10/2023 | 17/6/2026 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console. | |
| Modificada | Alta (8.8) | 1.1% | — | Cassianetworks Access Controller | 27/9/2023 | 17/6/2026 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks. | |
| Modificada | Media (5.3) | 1.1% | — | Cassianetworks Access Controller | 11/5/2023 | 17/6/2026 | Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users. | |
| Modificada | Alta (7.5) | 0.63% | — | Cassianetworks Access Controller | 14/10/2022 | 17/6/2026 | An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1. | |
| Modificada | Alta (7.5) | 1.6% | — | Integrated Dell Remote Access Controller 8 Firmware | 21/4/2022 | 17/6/2026 | Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting in a denial of service condition. | |
| Modificada | Alta (8.1) | 1.1% | — | Integrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC. | |
| Modificada | Alta (7.2) | 2.2% | — | Integrated Dell Remote Access Controller 8 FirmwareIntegrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system. | |
| Modificada | Media (5.3) | 4.2% | — | Integrated Dell Remote Access Controller 8 Firmware | 25/1/2022 | 17/6/2026 | Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver. | |
| Modificada | Media (6.1) | 1.2% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. | |
| Modificada | Alta (8.8) | 2.0% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. | |
| Modificada | Crítica (9.8) | 2.7% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input. | |
| Modificada | Crítica (9.8) | 2.7% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal. | |
| Modificada | Alta (8.3) | 1.9% | — | HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+14 | 18/10/2010 | 16/6/2026 | Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Micronet Network Access Controller Sp1910 | 8/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. |