Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

436 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)11%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getFileFromURL method of the…
ModificadaAlta (8.8)9.3%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the setAppFileBytes method of…
ModificadaAlta (8.8)59%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the saveAsText method of the…
ModificadaAlta (8.8)7.2%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (7.5)3.2%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the FlashValidatorServiceImpl class. The issue…
ModificadaAlta (7.5)3.2%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the FlashValidatorServiceImpl class. The issue…
ModificadaCrítica (9.8)12%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the decryptFile method of the FlashValidatorServiceImpl class. The issue results from the…
ModificadaMedia (6.1)0.64%—Teradici Pcoip Management Console17/8/202017/6/2026
Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active session if the user is exposed to a malicious payload.
ModificadaAlta (7.5)1.5%—Intel Raid WEB Console 313/8/202017/6/2026
Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (6.1)0.66%—Teradici Pcoip Management Console11/8/202017/6/2026
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
ModificadaAlta (7.8)0.37%—Vmware FusionVmware Horizon ClientVmware Remote Console10/7/202017/6/2026
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user…
ModificadaAlta (7)0.22%—Vmware FusionVmware Horizon ClientVmware Remote Console29/5/202017/6/2026
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with…
ModificadaAlta (7.5)2.1%—NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+1317/4/202017/6/2026
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
ModificadaBaja (3.7)2.5%—Oracle Java Advanced Management Console15/4/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is Java Advanced Management Console: 2.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.…
ModificadaAlta (8.1)1.5%—Teradici Pcoip Management Console25/3/202017/6/2026
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled. It is fixed in 20.01.1 and 19.11.2.
AnalizadaAlta (7.8)7.3%⚠ Explotación activa💥 ExploitVmware FusionVmware Horizon ClientVmware Remote Console17/3/202017/6/2026
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user…
ModificadaAlta (7.8)0.39%—Vmware Horizon ClientVmware Remote ConsoleVmware Workstation16/3/202017/6/2026
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the…
ModificadaAlta (7.8)0.72%—Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server16/2/202017/6/2026
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.
ModificadaAlta (7.8)0.29%—Intel Raid WEB Console 313/2/202017/6/2026
Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.29%—Intel Raid WEB Console 213/2/202017/6/2026
Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.6)1.2%—Eucalyptus Management Console31/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.77%—Eucalyptus Management Console27/1/202016/6/2026
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)0.29%—Intel Raid WEB Console 317/1/202017/6/2026
Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)0.54%—Redhat MRG Management Console30/12/201916/6/2026
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
ModificadaAlta (8.8)1.2%—Consolekit Project ConsolekitDebian LinuxRedhat Enterprise Linux13/11/201916/6/2026
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.