Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.12% | — | Dell PowerpathAI | 19/8/2026 | 20/8/2026 | Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Modificada | Media (5.5) | 0.12% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems. | |
| Modificada | Alta (7.3) | 0.18% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Powerpath | 30/5/2023 | 17/6/2026 | PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Media (4.8) | 0.34% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server. | |
| Modificada | Media (6.7) | 0.42% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root. | |
| Modificada | Media (6) | 0.18% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. | |
| Modificada | Alta (8.8) | 0.31% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions. | |
| Modificada | Alta (7.2) | 1.7% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user. | |
| Modificada | Alta (8.1) | 0.79% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. | |
| Modificada | Baja (2.7) | 0.43% | — | Dell Powerpath Management Appliance | 10/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Powerpath Management Appliance | 21/12/2021 | 17/6/2026 | Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges. | |
| Modificada | Media (6.4) | 0.74% | — | EMC Powerpath Virtual Appliance | 3/2/2017 | 17/6/2026 | EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (5) | 2.8% | — | EMC Powerpath Virtual Appliance | 5/4/2015 | 17/6/2026 | EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session. |