Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.23%—Solarwinds Dameware Mini Remote ControlAI2/6/202517/6/2026
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability.
ModificadaCrítica (9.1)4.0%—Solarwinds Dameware Mini Remote Control13/7/202117/6/2026
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
ModificadaCrítica (9.8)5.1%—Solarwinds Dameware Mini Remote Control8/10/201917/6/2026
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System…
ModificadaAlta (7.4)26%—Solarwinds Dameware Mini Remote Control7/6/201917/6/2026
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
ModificadaAlta (7.5)19%—Solarwinds Dameware Mini Remote Control2/5/201917/6/2026
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
ModificadaAlta (7.8)1.7%—Solarwinds Dameware Mini Remote Control7/9/201817/6/2026
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
ModificadaCrítica (9.8)51%—Dameware Mini Remote Control17/3/201617/6/2026
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
ModificadaAlta (7.5)4.8%—Solarwinds Dameware Mini Remote Control17/11/201517/6/2026
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.
ModificadaAlta (7.5)21%—Dameware Development Mini Remote Control Server8/9/200516/6/2026
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username.
ModificadaAlta (7.2)0.35%—Dameware Development Mini Remote ControlDameware Development NT Utilities2/5/200516/6/2026
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
ModificadaAlta (7.5)1.1%—Dameware Development Mini Remote Control Server24/3/200416/6/2026
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
ModificadaMedia (5)0.84%—Solarwinds Dameware Mini Remote Control23/3/200416/6/2026
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
ModificadaAlta (7.5)17%—Dameware Development Mini Remote Control Server17/2/200416/6/2026
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.