Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

436 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.51%—Google APP EngineAIGoogle Cloud ConsoleAI22/6/202622/6/2026
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and…
AplazadaAlta (7.1)0.60%—Capgo ConsoleAI12/6/202617/6/2026
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with…
AplazadaCrítica (9.4)0.60%—Veeam Service Provider ConsoleAI28/5/202617/6/2026
This vulnerability in Veeam Service Provider Console allows for remote code execution.
AnalizadaCrítica (9.3)1.3%⚠ Explotación activaNX Console27/5/202617/6/2026
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version…
AnalizadaCrítica (9.8)0.54%—IBM Total Storage Service ConsoleIBM Ts4500 IMC23/4/202617/6/2026
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Pendiente de análisisMedia (5.1)0.24%—Arcserve UDP ConsoleAI16/4/202617/6/2026
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
AplazadaAlta (8.7)0.44%—Console-surveyAI30/3/202617/6/2026
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs,…
AnalizadaMedia (5.3)0.24%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
AnalizadaMedia (4.9)0.42%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
AnalizadaMedia (4.3)0.27%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
AnalizadaAlta (8.5)0.19%—Dell UPS Multi-ups Management Console5/3/202617/6/2026
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.
AnalizadaAlta (8.4)0.20%—Dell UPS Multi-ups Management Console5/3/202617/6/2026
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.
AplazadaAlta (8.5)0.16%—Zilab Remote Console ServerAI11/2/202617/6/2026
Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with…
AnalizadaAlta (8.6)0.40%—IBM Aspera Console5/2/202617/6/2026
IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AplazadaCrítica (10)0.55%—Tmsglobalsoft TMS Management ConsoleAI22/1/202617/6/2026
File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via the Logo upload in /Customer/AddEdit
ModificadaMedia (6.5)1.00%—Tmsglobalsoft TMS Management Console22/1/20265/7/2026
A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" function in the profile dashboard does not neutralize directory traversal sequences (../) in the filePath parameter, allowing authenticated users to read arbitrary files,…
AnalizadaMedia (4.9)0.33%—IBM Aspera Console20/1/202617/6/2026
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
AplazadaAlta (8.5)0.16%—Cyclades Serial Console ServerAI13/1/202617/6/2026
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.
AplazadaAlta (8.7)0.42%—Gorilla TAG ConsoleAI25/11/202517/6/2026
Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched…
AplazadaAlta (8.5)0.17%—Remoteview PC Application ConsoleAI15/10/202517/6/2026
RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.
AplazadaMedia (5.8)0.52%—Blmon ConsoleAI9/9/202517/6/2026
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in an SSH session.
AnalizadaMedia (5.4)0.22%—IBM Hardware Management Console9/9/202517/6/2026
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaCrítica (9.4)1.3%—Marvell Qconvergeconsole31/7/202517/6/2026
Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Marvell QConvergeConsole. Authentication is…
AplazadaCrítica (9.4)4.7%—Escan WEB Management ConsoleAI25/7/202517/6/2026
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary commands via a specially crafted password…
AplazadaMedia (5.4)0.19%—SAP Data Services Management ConsoleAI8/7/202517/6/2026
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This…