Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.5% | — | Dell Kace K1000 System Management ApplianceAI | 5/8/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are… | |
| Modificada | Crítica (9.8) | 1.5% | — | Ecos System Management Appliance | 17/6/2018 | 17/6/2026 | Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access. | |
| Modificada | Alta (7.3) | 0.43% | — | Ecos System Management Appliance | 17/6/2018 | 17/6/2026 | Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment. | |
| Modificada | Alta (7.4) | 0.95% | — | Ecos System Management Appliance | 17/6/2018 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and configurations via IP spoofing during "Easy Enrollment." | |
| Modificada | Media (5.5) | 0.42% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying the 'Host' and 'X_Forwarded_For' HTTP headers in a POST request. An anonymous user can abuse this… | |
| Modificada | Crítica (9.8) | 2.0% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type). | |
| Modificada | Alta (8.8) | 43% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Quest Kace System Management Appliance | 31/5/2018 | 13/8/2026 | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. | |
| Modificada | Media (6.5) | 6.5% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script. | |
| Modificada | Crítica (9.8) | 1.4% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type). | |
| Modificada | Alta (8.8) | 2.1% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks. | |
| Modificada | Alta (8.8) | 3.0% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user… | |
| Modificada | Media (6.1) | 8.7% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting. | |
| Modificada | Alta (8.8) | 18% | — | Quest Kace System Management Appliance | 31/5/2018 | 17/6/2026 | In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows… |