Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

436 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.81%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.
ModificadaMedia (5.4)0.76%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
ModificadaMedia (6.1)0.81%💥 PoCEscanav Escan Management Console2/6/202317/6/2026
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
ModificadaMedia (6.1)0.84%💥 PoCEscanav Escan Management Console31/5/202317/6/2026
Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.
ModificadaCrítica (9.8)1.2%💥 PoCEscanav Escan Management Console31/5/202317/6/2026
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
ModificadaMedia (5.3)0.65%—Minio Console30/5/202317/6/2026
Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.
ModificadaCrítica (9)4.5%💥 ExploitEscanav Escan Management Console17/5/202317/6/2026
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
ModificadaAlta (7.2)4.3%💥 ExploitEscanav Escan Management Console17/5/202317/6/2026
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.
ModificadaMedia (4.8)0.44%—Byconsole Pickup | Delivery | Dine-in Date Time8/5/202317/6/2026
The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)0.97%—Tencent Vconsole26/4/202317/6/2026
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
ModificadaAlta (8.8)1.0%—Cisco Secure Network AnalyticsCisco Stealthwatch Management Console 2200 Firmware5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that is parsed into system memory. An attacker…
ModificadaMedia (6.1)0.52%—Console Project Console8/1/202317/6/2026
A vulnerability has been found in yanheven console and classified as problematic. Affected by this vulnerability is the function get_zone_hosts/AvailabilityZonesTable of the file openstack_dashboard/dashboards/admin/aggregates/tables.py. The manipulation leads to cross site scripting. The attack can be launched…
ModificadaMedia (4.9)0.45%—IBM Power System Ac922 (8335-gtg) FirmwareIBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Hardware Management Console 7063-cr2 Firmware22/8/202217/6/2026
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
ModificadaAlta (7.8)0.39%—Teradici Pcoip Management Console30/6/202217/6/2026
A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit…
ModificadaMedia (6.5)1.2%—Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server20/5/202217/6/2026
In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client…
ModificadaAlta (7.5)10%💥 ExploitFlyte Console17/5/202217/6/2026
FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other…
ModificadaBaja (2.7)0.66%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+1013/4/202217/6/2026
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
ModificadaAlta (7.5)1.5%—IBM System Storage Ds8000 Management Console Firmware11/4/202217/6/2026
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.
ModificadaCrítica (9.8)2.3%—Netflix Consoleme1/4/202217/6/2026
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaMedia (5.5)4.8%—Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+24/3/202217/6/2026
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
AnalizadaCrítica (10)98%⚠ Explotación activa💥 ExploitVmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+63/3/202217/6/2026
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Orbitaley — Vulnerabilidades