Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.2% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.5) | 1.3% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.1) | 1.2% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Crítica (9.8) | 0.68% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 1.3% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Crítica (9.1) | 1.5% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.5) | 1.4% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.5) | 1.2% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Crítica (9.8) | 1.5% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.4) | 18% | — | Marvell Qconvergeconsole | 7/7/2025 | 17/6/2026 | Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required… | |
| Analizada | Alta (7.2) | 0.21% | — | Checkpoint Smartconsole | 29/6/2025 | 17/6/2026 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them. | |
| Analizada | Alta (7.8) | 2.7% | — | Checkpoint Smartconsole | 19/6/2025 | 17/6/2026 | Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin). | |
| Analizada | Media (6.9) | 11% | — | Citrix Netscaler ConsoleCitrix Netscaler SDX | 17/6/2025 | 17/6/2026 | Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) | |
| Analizada | Media (5.4) | 0.22% | — | IBM Hardware Management Console R10.0 FirmwareIBM Hardware Management Console R9.4 FirmwareIBM Hardware Management Console R9.3 Firmware | 27/5/2025 | 17/6/2026 | IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (4.4) | 0.20% | — | Data Services Management ConsoleAI | 13/5/2025 | 17/6/2026 | The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to… | |
| Aplazada | Alta (7.3) | 0.20% | — | Mechrevo Control ConsoleAI | 5/5/2025 | 17/6/2026 | A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled… | |
| Analizada | Media (6.7) | 0.22% | — | IBM Hardware Management Console | 22/4/2025 | 17/6/2026 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM Hardware Management Console | 22/4/2025 | 17/6/2026 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source. | |
| Aplazada | Baja (2.5) | 0.12% | — | Soffid ConsoleAI | 21/4/2025 | 17/6/2026 | In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled. | |
| Analizada | Alta (8.8) | 0.25% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. |