Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2899▼ 147 respecto a la semana anterior
Críticas / altas1291▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.34% | — | Suse Spacewalk-javaAISuse ManagerAI | 27/5/2025 | 17/6/2026 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on users machines.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; SUSE Manager Server Module 4.3:… | |
| Aplazada | Media (5.7) | 0.35% | — | Suse ManagerAIRedhat Spacewalk-javaAI | 26/5/2025 | 17/6/2026 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; Container… | |
| Aplazada | Media (4.6) | 0.28% | — | Suse ManagerAISuse Spacewalk-webAI | 28/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container… | |
| Modificada | Alta (8.8) | 1.8% | — | Uyuni-project UyuniSpacewalk Project Spacewalk | 1/11/2021 | 17/6/2026 | Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead… | |
| Modificada | Crítica (9.8) | 4.3% | — | Redhat Spacewalk | 17/2/2020 | 17/6/2026 | A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the… | |
| Modificada | Crítica (9.8) | 3.1% | — | Redhat SatelliteRedhat Spacewalk | 2/7/2019 | 17/6/2026 | A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context… | |
| Modificada | Media (4.3) | 0.57% | — | Redhat SatelliteRedhat Spacewalk | 2/7/2019 | 17/6/2026 | It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. | |
| Modificada | Crítica (9.8) | 2.1% | — | Redhat SpacewalkRedhat Satellite | 27/7/2018 | 17/6/2026 | It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. | |
| Modificada | Alta (7.5) | 1.0% | — | Redhat SpacewalkRedhat Satellite | 14/3/2018 | 17/6/2026 | Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server. | |
| Modificada | Media (6.1) | 1.6% | — | Redhat SatelliteRedhat Spacewalk-java | 14/4/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot… | |
| Modificada | Media (5.4) | 1.2% | — | Redhat SatelliteRedhat Spacewalk-java | 14/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811. | |
| Modificada | Baja (3.5) | 1.5% | — | Redhat SatelliteRedhat SpacewalkSuse Manager | 15/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote authenticated users to inject arbitrary web script or HTML via the System Groups field. | |
| Modificada | Baja (3.5) | 1.5% | — | Redhat Network SatelliteRedhat SpacewalkSuse Manager | 15/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager Server+1 | 3/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3)… | |
| Modificada | Media (4.3) | 1.8% | — | Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager+1 | 22/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging. | |
| Modificada | Media (6) | 3.1% | — | Redhat Network ProxyRedhat SatelliteRedhat Spacewalk-java | 15/4/2014 | 16/6/2026 | The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat SatelliteRedhat Spacewalk-java | 1/4/2014 | 16/6/2026 | CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via the return_url parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Redhat SatelliteRedhat Satellite 5 Managed DBRedhat Spacewalk-javaRedhat Spacewalk-web+1 | 14/2/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) whereCriteria variable in a software channels search; (2) end_year, (3) start_hour, (4) end_am_pm, (5) end_day, (6) end_hour, (7)… | |
| Modificada | Baja (3.5) | 1.6% | — | Redhat SatelliteRedhat Satellite 5 Managed DBRedhat Spacewalk-java | 14/2/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call. | |
| Modificada | Media (5.4) | 1.5% | — | Redhat Network SatelliteRedhat Spacewalk | 5/2/2014 | 16/6/2026 | A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to information disclosure or unauthorized actions within the user's browser session. | |
| Modificada | Media (5.4) | 1.5% | — | Redhat Network SatelliteRedhat Spacewalk | 5/2/2014 | 16/6/2026 | A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially… | |
| Modificada | Media (5.5) | 2.0% | — | Redhat Network SatelliteRedhat Spacewalk | 5/2/2014 | 16/6/2026 | A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's… | |
| Modificada | Media (4.3) | 1.2% | — | Redhat Network SatelliteRedhat Spacewalk | 5/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat Network SatelliteRedhat Spacewalk | 5/2/2014 | 16/6/2026 | A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized… | |
| Modificada | Media (6.8) | 0.82% | — | Redhat Network Satellite ServerRedhat Spacewalk-java | 27/7/2011 | 16/6/2026 | A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying… |