Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.17%—Dell Device Management Agent1/7/20266/7/2026
Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaAlta (7.8)0.14%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaMedia (5.5)0.12%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.
AnalizadaMedia (4.4)0.11%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access.
AplazadaAlta (7.6)0.45%—Sinotrack Device Management InterfaceAI12/6/202517/6/2026
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A…
ModificadaAlta (8.6)0.86%—Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
AnalizadaCrítica (9.8)83%⚠ Explotación activa💥 ExploitYealink Device Management15/10/202117/6/2026
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
ModificadaAlta (7.5)2.2%—Invigo Automatic Device Management25/3/202117/6/2026
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.
ModificadaAlta (8.8)2.8%—Invigo Automatic Device Management25/3/202117/6/2026
The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.
ModificadaCrítica (9.8)1.6%—Invigo Automatic Device Management25/3/202117/6/2026
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.
ModificadaAlta (7.5)1.3%—Invigo Automatic Device Management25/3/202117/6/2026
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
ModificadaAlta (8.8)3.9%—Invigo Automatic Device Management25/3/202117/6/2026
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
ModificadaAlta (7.5)2.2%—Invigo Automatic Device Management25/3/202117/6/2026
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
ModificadaAlta (9.3)6.5%—IBM Tivoli Endpoint Manager Mobile Device Management6/12/201417/6/2026
IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2)…
Orbitaley — Vulnerabilidades