Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.6)0.37%—Pruvasoft Informatics Apinizer Management ConsoleAI18/7/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apinizer Management Console: before 2024.05.1.
AplazadaCrítica (9.9)0.44%—Pruvasoft Informatics Apinizer Management ConsoleAI18/7/202417/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: before 2024.05.1.
ModificadaAlta (8.6)0.46%—Bentley Assetwise Alim FOR TransportationBentley EB System Management Console22/12/202317/6/2026
Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before…
ModificadaAlta (7.8)0.16%—IBM Hardware Management Console16/10/202317/6/2026
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.
ModificadaMedia (5.4)0.81%—Escanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.
ModificadaMedia (5.4)0.81%—Escanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.
ModificadaMedia (5.4)0.81%—Escanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.
ModificadaMedia (5.4)0.76%—Escanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
ModificadaMedia (6.1)0.81%—Escanav Escan Management Console2/6/202317/6/2026
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
ModificadaMedia (6.1)0.84%—Escanav Escan Management Console31/5/202317/6/2026
Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.
ModificadaCrítica (9.8)1.2%—Escanav Escan Management Console31/5/202317/6/2026
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
ModificadaCrítica (9)4.5%—Escanav Escan Management Console17/5/202317/6/2026
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
ModificadaAlta (7.2)4.3%—Escanav Escan Management Console17/5/202317/6/2026
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.
ModificadaAlta (8.8)1.0%—Cisco Secure Network AnalyticsCisco Stealthwatch Management Console 2200 Firmware5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that is parsed into system memory. An attacker…
ModificadaMedia (4.9)0.45%—IBM Power System Ac922 (8335-gtg) FirmwareIBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Hardware Management Console 7063-cr2 Firmware22/8/202217/6/2026
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
ModificadaAlta (7.8)0.39%—Teradici Pcoip Management Console30/6/202217/6/2026
A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit…
ModificadaBaja (2.7)0.66%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+1013/4/202217/6/2026
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.
ModificadaAlta (7.5)1.1%—IBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Power Hardware Management Console (7063-cr2) Firmware4/2/202217/6/2026
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.
ModificadaMedia (5.9)0.99%—IBM Power Hardware Management Console (7063-cr1) FirmwareIBM Power System Cs822lc (8005-22n) FirmwareIBM Power System Cs821lc (8005-12n) FirmwareIBM Power System S822lc (8001-22c) Firmware+115/12/202117/6/2026
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.
ModificadaAlta (7.2)1.1%—HP Storeserv Management Console10/12/202117/6/2026
A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this…
ModificadaMedia (6.1)0.82%—Outsystems Lifetime Management ConsoleOutsystemsOutsystems Platform Server31/8/202117/6/2026
A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications. It could allow an unauthenticated remote attacker to craft and store malicious Feedback content into /ECT_Provider/, such that when the content is viewed (it can only be viewed by…
ModificadaAlta (7.8)0.30%—IBM Hardware Management Console19/7/202117/6/2026
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.
ModificadaMedia (6.1)0.72%—Teradici Pcoip Management Console7/7/20219/7/2026
In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.