Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.51% | — | Google APP EngineAIGoogle Cloud ConsoleAI | 22/6/2026 | 22/6/2026 | A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and… | |
| Aplazada | Alta (7.1) | 0.60% | — | Capgo ConsoleAI | 12/6/2026 | 17/6/2026 | Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with… | |
| Aplazada | Crítica (9.4) | 0.60% | — | Veeam Service Provider ConsoleAI | 28/5/2026 | 17/6/2026 | This vulnerability in Veeam Service Provider Console allows for remote code execution. | |
| Analizada | Crítica (9.3) | 1.3% | ⚠ Explotación activa | NX Console | 27/5/2026 | 17/6/2026 | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version… | |
| Analizada | Crítica (9.8) | 0.54% | — | IBM Total Storage Service ConsoleIBM Ts4500 IMC | 23/4/2026 | 17/6/2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Pendiente de análisis | Media (5.1) | 0.24% | — | Arcserve UDP ConsoleAI | 16/4/2026 | 17/6/2026 | UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure. | |
| Aplazada | Alta (8.7) | 0.44% | — | Console-surveyAI | 30/3/2026 | 17/6/2026 | A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs,… | |
| Analizada | Media (5.3) | 0.24% | — | IBM Aspera Console | 16/3/2026 | 17/6/2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy. | |
| Analizada | Media (4.9) | 0.42% | — | IBM Aspera Console | 16/3/2026 | 17/6/2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow. | |
| Analizada | Media (4.3) | 0.27% | — | IBM Aspera Console | 16/3/2026 | 17/6/2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency. | |
| Analizada | Alta (8.5) | 0.19% | — | Dell UPS Multi-ups Management Console | 5/3/2026 | 17/6/2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL. | |
| Analizada | Alta (8.4) | 0.20% | — | Dell UPS Multi-ups Management Console | 5/3/2026 | 17/6/2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges. | |
| Aplazada | Alta (8.5) | 0.16% | — | Zilab Remote Console ServerAI | 11/2/2026 | 17/6/2026 | Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with… | |
| Analizada | Alta (8.6) | 0.40% | — | IBM Aspera Console | 5/2/2026 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Aplazada | Crítica (10) | 0.55% | — | Tmsglobalsoft TMS Management ConsoleAI | 22/1/2026 | 17/6/2026 | File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via the Logo upload in /Customer/AddEdit | |
| Modificada | Media (6.5) | 1.00% | — | Tmsglobalsoft TMS Management Console | 22/1/2026 | 5/7/2026 | A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" function in the profile dashboard does not neutralize directory traversal sequences (../) in the filePath parameter, allowing authenticated users to read arbitrary files,… | |
| Analizada | Media (4.9) | 0.33% | — | IBM Aspera Console | 20/1/2026 | 17/6/2026 | IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user. | |
| Aplazada | Alta (8.5) | 0.16% | — | Cyclades Serial Console ServerAI | 13/1/2026 | 17/6/2026 | Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions. | |
| Aplazada | Alta (8.7) | 0.42% | — | Gorilla TAG ConsoleAI | 25/11/2025 | 17/6/2026 | Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched… | |
| Aplazada | Alta (8.5) | 0.17% | — | Remoteview PC Application ConsoleAI | 15/10/2025 | 17/6/2026 | RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Media (5.8) | 0.52% | — | Blmon ConsoleAI | 9/9/2025 | 17/6/2026 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in an SSH session. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Hardware Management Console | 9/9/2025 | 17/6/2026 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Crítica (9.4) | 1.3% | — | Marvell Qconvergeconsole | 31/7/2025 | 17/6/2026 | Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Marvell QConvergeConsole. Authentication is… | |
| Aplazada | Crítica (9.4) | 4.7% | — | Escan WEB Management ConsoleAI | 25/7/2025 | 17/6/2026 | A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary commands via a specially crafted password… | |
| Aplazada | Media (5.4) | 0.19% | — | SAP Data Services Management ConsoleAI | 8/7/2025 | 17/6/2026 | Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This… |