Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.13% | — | Drive Power ManagerAI | 26/4/2026 | 17/6/2026 | Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition. | |
| Analizada | Alta (7.8) | 0.18% | — | Dell Power Manager | 9/12/2024 | 17/6/2026 | Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges. | |
| Aplazada | Media (5.2) | 8.3% | — | Eaton Intelligent Power ManagerAI | 25/11/2024 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from certain resources by the IPM software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system | |
| Analizada | Alta (8.8) | 0.15% | — | Dell Power Manager | 22/8/2024 | 17/6/2026 | Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Power Manager | 6/2/2024 | 17/6/2026 | Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Power Manager | 27/7/2023 | 17/6/2026 | Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Power Manager | 7/4/2023 | 17/6/2026 | Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system. | |
| Modificada | Alta (8) | 0.42% | — | Eaton Intelligent Power Manager | 18/4/2022 | 17/6/2026 | Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |
| Modificada | Media (4.8) | 0.42% | — | Eaton Intelligent Power Manager | 18/4/2022 | 17/6/2026 | Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |
| Modificada | Media (4.8) | 0.50% | — | Eaton Intelligent Power Manager Infrastructure | 18/4/2022 | 17/6/2026 | Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |
| Modificada | Media (5.4) | 0.46% | — | Eaton Intelligent Power Manager | 1/4/2022 | 17/6/2026 | The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70. | |
| Modificada | Crítica (10) | 2.2% | — | Eaton Intelligent Power Manager | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to rouge SNMP server and… | |
| Modificada | Crítica (9.9) | 0.87% | — | Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to… | |
| Modificada | Crítica (10) | 27% | — | Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially crafted packets to delete the files on the… | |
| Modificada | Crítica (9.6) | 1.0% | — | Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with action removeBackground and server/node_upgrade_srv.js with action removeFirmware. An attacker can send specially crafted packets to… | |
| Modificada | Crítica (10) | 0.96% | — | Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to… | |
| Modificada | Alta (8.8) | 0.79% | — | Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector | 13/4/2021 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base. | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level. | |
| Modificada | Media (5.4) | 0.63% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an… | |
| Modificada | Alta (7.2) | 2.1% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage. | |
| Modificada | Alta (7.8) | 0.36% | — | Eaton Intelligent Power Manager | 7/5/2020 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with… | |
| Modificada | Alta (7.3) | 2.1% | — | Eaton Intelligent Power Manager | 7/5/2020 | 17/6/2026 | Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application. | |
| Modificada | Crítica (9.8) | 20% | — | Eaton Intelligent Power Manager | 7/6/2018 | 17/6/2026 | Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. | |
| Modificada | Alta (7.8) | 2.3% | — | HP Proliant SL Advanced Power ManagerHP Proliant SL Advanced Power Manager Firmware | 11/8/2011 | 16/6/2026 | The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | HP Power Manager | 14/3/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to… |