Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.32% | — | Precor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges. | |
| Aplazada | Alta (7.8) | 0.20% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code. | |
| Analizada | Baja (3.3) | 0.16% | — | IBM Aspera Console | 30/5/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Aspera Console | 30/5/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238645. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Aspera Console | 30/5/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238645. | |
| Aplazada | Crítica (9.3) | 0.94% | — | Netflix ConsolemeAI | 16/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0. | |
| Analizada | Crítica (9.9) | 1.6% | — | Veeam Service Provider Console | 14/5/2024 | 17/6/2026 | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. | |
| Aplazada | Baja (3.5) | 0.46% | — | Sequentech Admin-consoleAI | 1/4/2024 | 17/6/2026 | A vulnerability was found in sequentech admin-console up to 6.1.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Election Description Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 7.0.0-beta.1 is… | |
| Analizada | Crítica (9.1) | 0.53% | — | IBM Aspera Console | 23/2/2024 | 17/6/2026 | IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 239079. | |
| Modificada | Crítica (9.8) | 0.84% | — | Gttb GTB Central Console | 2/2/2024 | 17/6/2026 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value. | |
| Modificada | Alta (7.2) | 2.5% | — | Gttb GTB Central Console | 2/2/2024 | 17/6/2026 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an… | |
| Modificada | Media (6.1) | 0.34% | — | IBM Aspera Console | 25/12/2023 | 17/6/2026 | IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210322. | |
| Modificada | Alta (8.6) | 0.46% | — | Bentley Assetwise Alim FOR TransportationBentley EB System Management Console | 22/12/2023 | 17/6/2026 | Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before… | |
| Modificada | Crítica (9.8) | 15% | — | Qnap QTSQnap Multimedia ConsoleQnap Media Streaming Add-on | 3/11/2023 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia… | |
| Modificada | Media (6.1) | 0.33% | — | Byconsole Wooodt Lite | 17/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ByConsole WooODT Lite – WooCommerce Order Delivery or Pickup with Date Time Location plugin <= 2.4.6 versions. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Hardware Management Console | 16/10/2023 | 17/6/2026 | IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.92% | — | Qnap Multimedia Console | 22/9/2023 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 )… | |
| Modificada | Alta (7.5) | 0.72% | — | Doverfuelingsolutions Maglink LX WEB Console Configuration | 11/9/2023 | 17/6/2026 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 vulnerable to a path traversal attack, which could allow an attacker to access files stored on the system. | |
| Modificada | Alta (8.8) | 0.65% | — | Doverfuelingsolutions Maglink LX WEB Console Configuration | 11/9/2023 | 17/6/2026 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges. | |
| Modificada | Crítica (9.1) | 0.93% | — | Doverfuelingsolutions Maglink LX WEB Console Configuration | 11/9/2023 | 17/6/2026 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access. | |
| Modificada | Crítica (9.8) | 0.63% | — | Farmakom Remote Administration Console | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02. | |
| Modificada | Media (6.1) | 2.2% | — | Apache Felix Health Check Webconsole Plugin | 25/7/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin… | |
| Modificada | Media (5.4) | 0.81% | 💥 PoC | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter. | |
| Modificada | Media (5.4) | 0.81% | 💥 PoC | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath. |