Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

438 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.99%—Intel Raid WEB Console 314/11/201817/6/2026
Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege via remote access.
ModificadaMedia (5.5)0.36%—Intel Raid WEB Console 314/11/201817/6/2026
Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.
ModificadaMedia (6.5)1.1%—Intel Raid WEB Console10/10/201817/6/2026
Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose information via network access.
ModificadaAlta (7.4)1.1%—Vmware Airwatch Console5/10/201817/6/2026
The VMware Workspace ONE Unified Endpoint Management Console (A/W Console) 9.7.x prior to 9.7.0.3, 9.6.x prior to 9.6.0.7, 9.5.x prior to 9.5.0.16, 9.4.x prior to 9.4.0.22, 9.3.x prior to 9.3.0.25, 9.2.x prior to 9.2.3.27, and 9.1.x prior to 9.1.5.6 contains a SAML authentication bypass vulnerability which can be…
ModificadaMedia (5.3)99%💥 ExploitOpenbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1817/8/201817/6/2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
ModificadaMedia (6.7)0.31%—Pearsonvue Console 8Pearsonvue Iqsystem 73/8/201817/6/2026
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
ModificadaCrítica (9.8)4.8%—Redhat Openshift Container PlatformRedhat OpenstackRedhat Storage ConsoleRedhat Virtualization+519/7/201817/6/2026
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now…
ModificadaMedia (5.9)4.7%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise…
ModificadaAlta (8.3)3.2%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaBaja (3.7)4.4%—Oracle JDKOracle JREOracle JrockitDebian Linux+2218/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaAlta (8.3)1.9%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaAlta (8.3)2.6%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require…
ModificadaMedia (4.3)3.1%—Oracle JDKOracle JREHP XP7 Command ViewRedhat Satellite+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9)2.1%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in…
ModificadaAlta (7)0.33%—MongodbRedhat Storage Console6/7/201817/6/2026
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.
ModificadaCrítica (9.8)2.3%—Console-io Project Console-io31/5/201817/6/2026
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if console-io was running from root, the attacker…
ModificadaMedia (6.5)2.2%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
ModificadaMedia (6.5)1.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has an XXE issue.
ModificadaMedia (6.5)1.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.
ModificadaAlta (8.8)5.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.
ModificadaAlta (7.8)0.76%💥 ExploitVertiv Watchdog Console20/4/201817/6/2026
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.
ModificadaMedia (4.8)2.0%💥 ExploitVertiv Watchdog Console20/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description.
ModificadaMedia (4.9)8.1%💥 ExploitVertiv Watchdog Console20/4/201817/6/2026
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.
ModificadaMedia (6.1)0.64%—IBM Power Hardware Management Console20/4/201817/6/2026
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163.
ModificadaAlta (8.3)4.9%—Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+1319/4/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction…