Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
438 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.7% | — | Redhat Gluster Storage Management ConsoleRedhat Gluster Storage ServerRedhat Storage Native Client | 7/6/2016 | 17/6/2026 | The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | IBM Sterling B2B IntegratorIBM Sterling IntegratorIBM Tivoli Common ReportingIBM Watson Content Analytics+3 | 2/1/2016 | 17/6/2026 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library. | |
| Modificada | Alta (10) | 35% | — | Avira Management Console | 21/9/2015 | 17/6/2026 | Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Microsoft Live Meeting ConsoleMicrosoft LyncMicrosoft OfficeMicrosoft Windows Server 2008+1 | 9/9/2015 | 17/6/2026 | Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted OpenType font,… | |
| Modificada | Media (4.3) | 45% | 💥 Exploit | Rubyonrails WEB Console | 26/7/2015 | 17/6/2026 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request. | |
| Modificada | Media (6.5) | 8.9% | 💥 Exploit | Mulesoft Mule Enterprise Management Console | 20/11/2014 | 17/6/2026 | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but… | |
| Modificada | Alta (7.1) | 7.6% | 💥 Exploit | IBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware | 17/8/2014 | 17/6/2026 | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter. | |
| Modificada | Media (6.3) | 4.1% | 💥 Exploit | IBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware | 17/8/2014 | 17/6/2026 | prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | IBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware | 17/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php. | |
| Modificada | Media (6.8) | 0.51% | — | Sophos Enterprise Console | 25/6/2014 | 17/6/2026 | Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen. | |
| Modificada | Baja (1.9) | 0.48% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network. | |
| Modificada | Baja (3.5) | 0.92% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown… | |
| Modificada | Alta (8.5) | 6.1% | 💥 Exploit | IBM Global Console Manager 16 FirmwareIBM Global Console Manager 32 Firmware | 21/8/2013 | 16/6/2026 | ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter. | |
| Modificada | Baja (2.1) | 0.32% | — | GlusterfsRedhat Storage Management ConsoleRedhat Storage Native ClientRedhat Storage Server | 9/4/2013 | 16/6/2026 | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different… | |
| Modificada | Alta (7.5) | 1.5% | 💥 Exploit | Verifone Vericentre WEB Console | 15/11/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter. | |
| Modificada | Crítica (9.8) | 6.6% | — | Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+3 | 22/10/2012 | 16/6/2026 | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object. | |
| Modificada | Media (4.3) | 1.6% | — | IBM Power Hardware Management Console | 17/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.35% | — | IBM Power Hardware Management Console FirmwareIBM Systems Director Management Console Firmware | 6/8/2012 | 16/6/2026 | IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a… | |
| Modificada | Media (5) | 52% | 💥 Exploit | Landesk Lenovo Thinkmanagement Console | 18/2/2012 | 16/6/2026 | Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Landesk Lenovo Thinkmanagement Console | 18/2/2012 | 16/6/2026 | Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cyberoam Central Console | 12/2/2012 | 16/6/2026 | Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action. | |
| Modificada | Alta (10) | 13% | — | HP Centralized Management Console SoftwareHP San/iqHP Storageworks P4000 Virtual SAN Appliance | 16/11/2011 | 16/6/2026 | Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request. | |
| Modificada | Alta (7.5) | 1.4% | — | Opengear Console Server FirmwareOpengear Acm5000 Console ServerOpengear Cm4000 Console ServerOpengear Im4004-5 Console Server+3 | 9/11/2011 | 16/6/2026 | Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors. |