Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

436 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)2.4%—Entando Admin Console2/8/202117/6/2026
A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with command execution via freemarker.template.utility.Execute
ModificadaAlta (7.8)0.30%—IBM Hardware Management Console19/7/202117/6/2026
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.
ModificadaMedia (6.5)3.0%—Apache SshdOracle Banking PaymentsOracle Banking Trade FinanceOracle Banking Treasury Management+512/7/202117/6/2026
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
ModificadaMedia (6.1)0.72%—Teradici Pcoip Management Console7/7/20219/7/2026
In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.
ModificadaAlta (7.8)1.5%—Vmware APP VolumesVmware Remote ConsoleVmware Tools23/6/202117/6/2026
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a…
ModificadaMedia (5.9)2.2%—Redhat XnioRedhat Jboss BrmsRedhat Jboss Data GridRedhat Jboss Data Virtualization+102/6/202117/6/2026
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
ModificadaCrítica (9.8)1.8%—Qnap QTSQnap Media Streaming Add-onQnap Multimedia Console17/4/202117/6/2026
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the…
ModificadaAlta (8.6)0.95%—Outsystems Lifetime Management ConsoleOutsystemsOutsystems Platform Server12/4/202117/6/2026
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
ModificadaMedia (5.3)82%💥 ExploitEclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+131/4/202117/6/2026
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive…
ModificadaBaja (2.7)4.2%—Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+191/4/202117/6/2026
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
ModificadaMedia (5.9)4.9%—NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+1430/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not…
ModificadaMedia (5.3)1.4%—Redhat ResteasyNetapp Oncommand InsightQuarkusOracle Communications Cloud Native Core Console26/3/202117/6/2026
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this…
ModificadaMedia (6.1)6.2%💥 ExploitTriconsole Datepicker Calendar25/2/202117/6/2026
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.
ModificadaAlta (7.8)0.27%—Checkpoint Smartconsole20/1/202117/6/2026
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.
ModificadaAlta (8.1)1.7%—Marvell Qconvergeconsole18/12/202017/6/2026
Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbitrary files on disk as SYSTEM or root.
ModificadaMedia (6.1)0.77%—Qnap Multimedia Console10/12/202017/6/2026
This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.
ModificadaAlta (7.4)2.9%—Hibernate ORMDebian LinuxQuarkusOracle Communications Cloud Native Core Console+12/12/202017/6/2026
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly…
ModificadaCrítica (9.8)2.2%—HP Storeserv Management Console26/10/202017/6/2026
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR…
ModificadaAlta (7)4.4%—Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+1423/10/202017/6/2026
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared…
ModificadaAlta (8.8)1.3%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
ModificadaMedia (5.4)0.52%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
ModificadaAlta (7.8)0.43%—Kaspersky Security CenterKaspersky Security Center WEB Console2/9/202017/6/2026
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
ModificadaAlta (8.8)10%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the decryptFile method of the…
ModificadaAlta (8.8)7.5%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file.…
ModificadaAlta (8.8)10%—Marvell Qconvergeconsole25/8/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the writeObjectToConfigFile…
Orbitaley — Vulnerabilidades