Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

436 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.31%—IBM Aspera Console14/4/202517/6/2026
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.
AnalizadaAlta (7.5)0.22%—IBM Aspera Console14/4/202517/6/2026
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (5.4)0.23%—IBM Aspera Console14/4/202517/6/2026
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.23%—IBM Aspera Console14/4/202517/6/2026
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
ModificadaMedia (4.3)0.30%—IBM Aspera Console14/4/202517/6/2026
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
AplazadaMedia (4.3)0.50%—Redhat Openshift ConsoleAI19/3/20253/9/2026
A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can…
AnalizadaMedia (5.6)0.57%—Apache Felix Http Webconsole Plugin12/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
AnalizadaAlta (8.8)13%—Citrix Netscaler AgentCitrix Netscaler Console20/2/202517/6/2026
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
ModificadaMedia (5.3)0.42%—Byconsole Wooodt Lite18/2/202517/6/2026
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a publicly visible error message. This makes it…
AnalizadaMedia (6.5)0.51%—IBM Power Hardware Management Console14/2/202517/6/2026
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
AnalizadaMedia (6.1)0.69%—Apache Felix Webconsole10/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
ModificadaMedia (4.8)0.46%—Redhat HAL Management Console14/1/202519/8/2026
A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”,…
ModificadaAlta (8.8)0.97%—Byconsole Wooodt Lite2/1/202517/6/2026
Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6.
AplazadaAlta (7.1)0.51%—Skupper ConsoleAI24/12/202418/6/2026
A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a user sets up across a hybrid multi-cloud environment. When the default authentication method is used, a random password is generated for the "admin" user and is…
AplazadaBaja (3.7)0.38%—Jerod Santo Wordpress ConsoleAI9/12/202417/6/2026
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.
AnalizadaMedia (6.5)0.25%—Veeam Service Provider Console4/12/202417/6/2026
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
AnalizadaAlta (7.8)0.13%—Dell Networker Management Console3/12/202417/6/2026
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AplazadaMedia (5.3)0.58%—Openshift ConsoleAI25/11/202417/6/2026
A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed services that aren't readily available to clients due to network…
AnalizadaAlta (7.3)0.27%—AMD Provisioning Console12/11/202417/6/2026
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AnalizadaAlta (7.3)0.27%—AMD Management Console12/11/202417/6/2026
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
ModificadaCrítica (9.8)53%—Lubus WP Query Console28/10/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.
AnalizadaAlta (8.7)0.45%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
AnalizadaCrítica (10)0.79%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
AnalizadaCrítica (10)0.79%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
AnalizadaCrítica (9.3)0.51%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.