Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
438 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.99% | — | Intel Raid WEB Console 3 | 14/11/2018 | 17/6/2026 | Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege via remote access. | |
| Modificada | Media (5.5) | 0.36% | — | Intel Raid WEB Console 3 | 14/11/2018 | 17/6/2026 | Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access. | |
| Modificada | Media (6.5) | 1.1% | — | Intel Raid WEB Console | 10/10/2018 | 17/6/2026 | Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose information via network access. | |
| Modificada | Alta (7.4) | 1.1% | — | Vmware Airwatch Console | 5/10/2018 | 17/6/2026 | The VMware Workspace ONE Unified Endpoint Management Console (A/W Console) 9.7.x prior to 9.7.0.3, 9.6.x prior to 9.6.0.7, 9.5.x prior to 9.5.0.16, 9.4.x prior to 9.4.0.22, 9.3.x prior to 9.3.0.25, 9.2.x prior to 9.2.3.27, and 9.1.x prior to 9.1.5.6 contains a SAML authentication bypass vulnerability which can be… | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Openbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+18 | 17/8/2018 | 17/6/2026 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. | |
| Modificada | Media (6.7) | 0.31% | — | Pearsonvue Console 8Pearsonvue Iqsystem 7 | 3/8/2018 | 17/6/2026 | The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges. | |
| Modificada | Crítica (9.8) | 4.8% | — | Redhat Openshift Container PlatformRedhat OpenstackRedhat Storage ConsoleRedhat Virtualization+5 | 19/7/2018 | 17/6/2026 | Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now… | |
| Modificada | Media (5.9) | 4.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+16 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise… | |
| Modificada | Alta (8.3) | 3.2% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Baja (3.7) | 4.4% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+22 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (8.3) | 1.9% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Alta (8.3) | 2.6% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (4.3) | 3.1% | — | Oracle JDKOracle JREHP XP7 Command ViewRedhat Satellite+16 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9) | 2.1% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in… | |
| Modificada | Alta (7) | 0.33% | — | MongodbRedhat Storage Console | 6/7/2018 | 17/6/2026 | The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text. | |
| Modificada | Crítica (9.8) | 2.3% | — | Console-io Project Console-io | 31/5/2018 | 17/6/2026 | console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if console-io was running from root, the attacker… | |
| Modificada | Media (6.5) | 2.2% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue. | |
| Modificada | Media (6.5) | 1.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has an XXE issue. | |
| Modificada | Media (6.5) | 1.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role. | |
| Modificada | Alta (8.8) | 5.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality. | |
| Modificada | Alta (7.8) | 0.76% | 💥 Exploit | Vertiv Watchdog Console | 20/4/2018 | 17/6/2026 | Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml. | |
| Modificada | Media (4.8) | 2.0% | 💥 Exploit | Vertiv Watchdog Console | 20/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description. | |
| Modificada | Media (4.9) | 8.1% | 💥 Exploit | Vertiv Watchdog Console | 20/4/2018 | 17/6/2026 | XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data. | |
| Modificada | Media (6.1) | 0.64% | — | IBM Power Hardware Management Console | 20/4/2018 | 17/6/2026 | IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163. | |
| Modificada | Alta (8.3) | 4.9% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+13 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction… |