Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.22% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. | |
| Modificada | Media (4.3) | 0.30% | — | IBM Aspera Console | 14/4/2025 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document. | |
| Aplazada | Media (4.3) | 0.50% | — | Redhat Openshift ConsoleAI | 19/3/2025 | 3/9/2026 | A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can… | |
| Analizada | Media (5.6) | 0.57% | — | Apache Felix Http Webconsole Plugin | 12/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue. | |
| Analizada | Alta (8.8) | 13% | — | Citrix Netscaler AgentCitrix Netscaler Console | 20/2/2025 | 17/6/2026 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | |
| Modificada | Media (5.3) | 0.42% | — | Byconsole Wooodt Lite | 18/2/2025 | 17/6/2026 | The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a publicly visible error message. This makes it… | |
| Analizada | Media (6.5) | 0.51% | — | IBM Power Hardware Management Console | 14/2/2025 | 17/6/2026 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Media (6.1) | 0.69% | — | Apache Felix Webconsole | 10/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue. | |
| Modificada | Media (4.8) | 0.46% | — | Redhat HAL Management Console | 14/1/2025 | 19/8/2026 | A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”,… | |
| Modificada | Alta (8.8) | 0.97% | — | Byconsole Wooodt Lite | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6. | |
| Aplazada | Alta (7.1) | 0.51% | — | Skupper ConsoleAI | 24/12/2024 | 18/6/2026 | A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a user sets up across a hybrid multi-cloud environment. When the default authentication method is used, a random password is generated for the "admin" user and is… | |
| Aplazada | Baja (3.7) | 0.38% | — | Jerod Santo Wordpress ConsoleAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9. | |
| Analizada | Media (6.5) | 0.25% | — | Veeam Service Provider Console | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Networker Management Console | 3/12/2024 | 17/6/2026 | Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Aplazada | Media (5.3) | 0.58% | — | Openshift ConsoleAI | 25/11/2024 | 17/6/2026 | A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed services that aren't readily available to clients due to network… | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Provisioning Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Management Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Modificada | Crítica (9.8) | 53% | — | Lubus WP Query Console | 28/10/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0. | |
| Analizada | Alta (8.7) | 0.45% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. | |
| Analizada | Crítica (10) | 0.79% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands. | |
| Analizada | Crítica (10) | 0.79% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands. | |
| Analizada | Crítica (9.3) | 0.51% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly. |