Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.68% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed. | |
| Analizada | Alta (8.7) | 0.36% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting. | |
| Analizada | Alta (7.5) | 0.43% | — | IBM Aspera Console | 25/9/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. | |
| Analizada | Alta (8) | 0.64% | — | IBM Aspera Console | 25/9/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Analizada | Media (5.7) | 0.22% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (5.7) | 0.22% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (5.7) | 0.23% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access. | |
| Analizada | Alta (7.8) | 0.13% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.14% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.5) | 0.15% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.7) | 0.23% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (5.5) | 0.13% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.5) | 0.15% | — | Intel Raid WEB Console | 16/9/2024 | 17/6/2026 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8) | 0.67% | — | Openshift ConsoleAI | 21/8/2024 | 11/8/2026 | An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application… | |
| Analizada | Crítica (9.8) | 1.00% | — | Escanav Escan Management Console | 20/8/2024 | 17/6/2026 | eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. | |
| Aplazada | Media (5.3) | 0.42% | — | Openshift ConsoleAI | 26/7/2024 | 17/6/2026 | A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider ("openShiftAuth") is set, these functions do not perform any authentication checks, relying instead on the targeted service to… | |
| Aplazada | Media (6.5) | 0.36% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Crítica (9.6) | 0.37% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Crítica (9.9) | 0.44% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Analizada | Alta (7.1) | 0.74% | — | Citrix Netscaler AgentCitrix Netscaler ConsoleCitrix Netscaler SDX | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX | |
| Analizada | Crítica (9.4) | 21% | — | Citrix Netscaler Console | 10/7/2024 | 17/6/2026 | Sensitive information disclosure in NetScaler Console | |
| Modificada | Media (5.4) | 0.31% | — | Trellix Xconsole | 13/6/2024 | 17/6/2026 | An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end… | |
| Aplazada | Alta (8) | 0.28% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges. | |
| Aplazada | Alta (8.8) | 0.32% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information. |