Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.09% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service. | |
| Analizada | Media (6.7) | 0.13% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information. | |
| Analizada | Media (6.7) | 0.38% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink. | |
| Analizada | Alta (7.2) | 0.30% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system. | |
| Analizada | Alta (8.4) | 0.67% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system. | |
| Analizada | Crítica (9.1) | 0.36% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is… | |
| Analizada | Alta (7.2) | 1.0% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system. | |
| Analizada | Media (4.9) | 0.29% | — | Dell Cloudlink | 14/8/2025 | 17/6/2026 | Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Alta (7.2) | 0.37% | — | Dell Cloudlink | 2/8/2024 | 17/6/2026 | CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the… | |
| Analizada | Media (5.5) | 0.12% | — | Dell Cloudlink | 28/6/2024 | 17/6/2026 | Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure. | |
| Modificada | Alta (7.5) | 0.42% | — | Dell Cloudlink | 16/5/2023 | 17/6/2026 | CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure. | |
| Modificada | Alta (8.2) | 0.20% | — | Dell Cloudlink | 1/9/2022 | 17/6/2026 | Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dell Cloudlink | 1/9/2022 | 17/6/2026 | Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system. | |
| Modificada | Media (6.5) | 0.64% | — | Dell Cloudlink | 26/5/2022 | 17/6/2026 | Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks. | |
| Modificada | Alta (7.2) | 2.1% | — | Dell Cloudlink | 23/11/2021 | 17/6/2026 | Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.… | |
| Modificada | Crítica (9.1) | 1.1% | — | Dell Cloudlink | 23/11/2021 | 17/6/2026 | Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may potentially exploit this vulnerability to gain unauthorized access to the system. | |
| Modificada | Alta (7.5) | 0.97% | — | Huawei Cloudlink Board FirmwareHuawei Dp300 FirmwareHuawei Rse6500 FirmwareHuawei Te60 Firmware | 17/2/2020 | 17/6/2026 | Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60 versions V500R002C00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C10, V600R019C00, and V600R019C00SPC100 have an information leak vulnerability. An… | |
| Modificada | Media (6.5) | 0.42% | — | Huawei Cloudlink Phone 7900 Firmware | 13/8/2019 | 17/6/2026 | The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can perform man-in-the-middle attacks, leading to the affected phones registered abnormally, affecting… |