Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.7)1.3%—Oracle Java Advanced Management Console19/10/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced…
ModificadaMedia (5.3)3.1%—Oracle Java Advanced Management Console19/10/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaBaja (3.7)1.8%—Oracle Java Advanced Management Console19/10/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaAlta (7.4)1.6%—Oracle Java Advanced Management Console8/8/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java…
ModificadaMedia (6.1)1.7%—Oracle Java Advanced Management Console8/8/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management…
ModificadaMedia (5.3)2.5%—Oracle Java Advanced Management Console8/8/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management…
ModificadaAlta (7.4)1.4%—Oracle Java Advanced Management Console8/8/201717/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Java Advanced Management…
ModificadaMedia (4.6)0.47%—Kernel Util-linuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+511/4/201717/6/2026
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
ModificadaAlta (7.8)0.34%—IBM Power Hardware Management Console20/3/201717/6/2026
IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.
ModificadaMedia (6.8)0.44%—IBM Hardware Management Console7/7/201617/6/2026
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.
ModificadaMedia (6.5)1.7%—Redhat Gluster Storage Management ConsoleRedhat Gluster Storage ServerRedhat Storage Native Client7/6/201617/6/2026
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.
ModificadaAlta (10)35%—Avira Management Console21/9/201517/6/2026
Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.
ModificadaMedia (6.5)8.9%💥 ExploitMulesoft Mule Enterprise Management Console20/11/201417/6/2026
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but…
ModificadaBaja (2.1)0.32%—GlusterfsRedhat Storage Management ConsoleRedhat Storage Native ClientRedhat Storage Server9/4/201316/6/2026
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different…
ModificadaCrítica (9.8)6.6%—Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+322/10/201216/6/2026
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
ModificadaMedia (4.3)1.6%—IBM Power Hardware Management Console17/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.35%—IBM Power Hardware Management Console FirmwareIBM Systems Director Management Console Firmware6/8/201216/6/2026
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a…
ModificadaMedia (5)52%💥 ExploitLandesk Lenovo Thinkmanagement Console18/2/201216/6/2026
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.
ModificadaAlta (7.5)69%💥 ExploitLandesk Lenovo Thinkmanagement Console18/2/201216/6/2026
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a…
ModificadaAlta (10)13%—HP Centralized Management Console SoftwareHP San/iqHP Storageworks P4000 Virtual SAN Appliance16/11/201116/6/2026
Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.
ModificadaAlta (10)11%—Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+1911/12/200916/6/2026
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)…
ModificadaAlta (9.3)1.3%—IBM Hardware Management Console28/5/200916/6/2026
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are…
ModificadaAlta (10)1.8%—IBM Hardware Management Console20/1/200916/6/2026
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.
ModificadaMedia (5)2.1%—IBM Hardware Management Console10/11/200816/6/2026
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.
ModificadaMedia (5)3.1%💥 ExploitMicroworld Technologies EscanMicroworld Technologies Escan Management ConsoleMicroworld Technologies Escan Server10/3/200816/6/2026
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.
Orbitaley — Vulnerabilidades