Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)0.95%—Outsystems Lifetime Management ConsoleOutsystemsOutsystems Platform Server12/4/202117/6/2026
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
ModificadaCrítica (9.8)2.2%—HP Storeserv Management Console26/10/202017/6/2026
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR…
ModificadaMedia (6.1)0.64%—Teradici Pcoip Management Console17/8/202017/6/2026
Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active session if the user is exposed to a malicious payload.
ModificadaMedia (6.1)0.66%—Teradici Pcoip Management Console11/8/202017/6/2026
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
ModificadaBaja (3.7)2.5%—Oracle Java Advanced Management Console15/4/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is Java Advanced Management Console: 2.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.…
ModificadaAlta (8.1)1.5%—Teradici Pcoip Management Console25/3/202017/6/2026
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled. It is fixed in 20.01.1 and 19.11.2.
ModificadaCrítica (9.6)1.2%—Eucalyptus Management Console31/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.77%—Eucalyptus Management Console27/1/202016/6/2026
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.54%—Redhat MRG Management Console30/12/201916/6/2026
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
ModificadaMedia (6.3)0.97%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.2)1.4%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.3)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (8.8)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaMedia (4.8)0.55%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaCrítica (9.4)4.3%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaMedia (6.1)1.5%—Oracle Java Advanced Management Console16/1/201917/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaMedia (6.5)2.2%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
ModificadaMedia (6.5)1.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has an XXE issue.
ModificadaMedia (6.5)1.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.
ModificadaAlta (8.8)5.1%—Digitalguardian Management Console20/4/201817/6/2026
Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.
ModificadaMedia (6.1)0.64%—IBM Power Hardware Management Console20/4/201817/6/2026
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163.
ModificadaAlta (8)0.49%—Symantec Management Console16/4/201817/6/2026
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request…
ModificadaBaja (3.7)1.9%—Oracle Java Advanced Management Console18/1/201817/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaMedia (6.8)1.1%—Symantec Management Console20/11/201717/6/2026
Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are…
ModificadaMedia (4.8)1.0%—Oracle Java Advanced Management Console19/10/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Java Advanced Management…