Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

438 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.7%—Redhat Gluster Storage Management ConsoleRedhat Gluster Storage ServerRedhat Storage Native Client7/6/201617/6/2026
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.
AnalizadaCrítica (9.8)92%⚠ Explotación activaOracle JDKOracle JREOracle JrockitOracle Linux+3421/4/201617/6/2026
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitIBM Sterling B2B IntegratorIBM Sterling IntegratorIBM Tivoli Common ReportingIBM Watson Content Analytics+32/1/201617/6/2026
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
ModificadaAlta (10)35%—Avira Management Console21/9/201517/6/2026
Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.
ModificadaAlta (9.3)36%💥 ExploitMicrosoft Live Meeting ConsoleMicrosoft LyncMicrosoft OfficeMicrosoft Windows Server 2008+19/9/201517/6/2026
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted OpenType font,…
ModificadaMedia (4.3)45%💥 ExploitRubyonrails WEB Console26/7/201517/6/2026
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
ModificadaMedia (6.5)8.9%💥 ExploitMulesoft Mule Enterprise Management Console20/11/201417/6/2026
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but…
ModificadaAlta (7.1)7.6%💥 ExploitIBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware17/8/201417/6/2026
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.
ModificadaMedia (6.3)4.1%💥 ExploitIBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware17/8/201417/6/2026
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
ModificadaMedia (4.3)3.5%💥 ExploitIBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware17/8/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.
ModificadaMedia (6.8)0.51%—Sophos Enterprise Console25/6/201417/6/2026
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
ModificadaBaja (1.9)0.48%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an…
ModificadaMedia (4.3)1.1%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
ModificadaBaja (3.5)0.92%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown…
ModificadaAlta (8.5)6.1%💥 ExploitIBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware21/8/201316/6/2026
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
ModificadaBaja (2.1)0.32%—GlusterfsRedhat Storage Management ConsoleRedhat Storage Native ClientRedhat Storage Server9/4/201316/6/2026
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different…
ModificadaAlta (7.5)1.5%💥 ExploitVerifone Vericentre WEB Console15/11/201216/6/2026
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
ModificadaCrítica (9.8)6.6%—Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+322/10/201216/6/2026
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
ModificadaMedia (4.3)1.6%—IBM Power Hardware Management Console17/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.35%—IBM Power Hardware Management Console FirmwareIBM Systems Director Management Console Firmware6/8/201216/6/2026
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a…
ModificadaMedia (5)52%💥 ExploitLandesk Lenovo Thinkmanagement Console18/2/201216/6/2026
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.
ModificadaAlta (7.5)69%💥 ExploitLandesk Lenovo Thinkmanagement Console18/2/201216/6/2026
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a…
ModificadaAlta (7.5)2.4%💥 ExploitCyberoam Central Console12/2/201216/6/2026
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.
ModificadaAlta (10)13%—HP Centralized Management Console SoftwareHP San/iqHP Storageworks P4000 Virtual SAN Appliance16/11/201116/6/2026
Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.
ModificadaAlta (7.5)1.4%—Opengear Console Server FirmwareOpengear Acm5000 Console ServerOpengear Cm4000 Console ServerOpengear Im4004-5 Console Server+39/11/201116/6/2026
Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors.