Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.17% | — | Dell Device Management Agent | 1/7/2026 | 6/7/2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service. | |
| Analizada | Media (4.4) | 0.11% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access. | |
| Aplazada | Alta (7.6) | 0.45% | — | Sinotrack Device Management InterfaceAI | 12/6/2025 | 17/6/2026 | A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A… | |
| Modificada | Alta (8.6) | 0.86% | — | Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform | 20/1/2023 | 17/6/2026 | A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 Exploit | Yealink Device Management | 15/10/2021 | 17/6/2026 | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | |
| Modificada | Alta (7.5) | 2.2% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application. | |
| Modificada | Alta (8.8) | 2.8% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application. | |
| Modificada | Crítica (9.8) | 1.6% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database. | |
| Modificada | Alta (7.5) | 1.3% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application. | |
| Modificada | Alta (8.8) | 3.9% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application. | |
| Modificada | Alta (7.5) | 2.2% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application. | |
| Modificada | Alta (9.3) | 6.5% | — | IBM Tivoli Endpoint Manager Mobile Device Management | 6/12/2014 | 17/6/2026 | IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2)… |