Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… | |
| Modificada | Alta (7.4) | 1.9% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user… | |
| Modificada | Alta (8.8) | 3.0% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete… | |
| Modificada | Crítica (9.8) | 14% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 17/7/2017 | 17/6/2026 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A… | |
| Modificada | Media (5.4) | 1.1% | — | EMC Vipr SRM | 30/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.76% | — | EMC Vipr SRM | 18/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.40% | — | EMC Vipr SRM | 18/9/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files. | |
| Modificada | Alta (7.6) | 0.72% | — | EMC Vipr SRM | 18/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.5% | — | EMC Vipr SRM | 18/9/2016 | 17/6/2026 | EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack. | |
| Modificada | Alta (8.8) | 3.6% | — | EMC Vipr SRM | 20/4/2016 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (4) | 7.4% | — | EMC Vipr SRMEMC Watch4net | 21/1/2015 | 17/6/2026 | Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL. | |
| Modificada | Media (6.5) | 2.9% | — | EMC Watch4netEMC Vipr SRM | 21/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file. | |
| Modificada | Media (5) | 7.6% | — | EMC Watch4netEMC Vipr SRM | 21/1/2015 | 17/6/2026 | EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack. | |
| Modificada | Baja (3.5) | 1.6% | — | EMC Watch4netEMC Vipr SRM | 21/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged access to set crafted values of unspecified fields. |