Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.36% | — | Apache KafkaAIStreamshub Console FOR Apache KafkaAI | 28/9/2026 | 30/9/2026 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to… | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Openshift ConsoleAI | 23/9/2026 | 1/10/2026 | A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests… | |
| Pendiente de análisis | Alta (7.2) | 0.33% | — | Openshift ConsoleAIOpenshift CatalogdAI | 23/9/2026 | 1/10/2026 | A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the… | |
| Pendiente de análisis | Crítica (9.3) | 0.80% | — | Openshift ConsoleAI | 18/9/2026 | 1/10/2026 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | IBM MQ ConsoleAI | 18/9/2026 | 18/9/2026 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks. | |
| Pendiente de análisis | Alta (8.4) | 0.48% | — | 389 Project 389 DS BaseAICockpit 389 ConsoleAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN… | |
| Analizada | Alta (7.3) | 0.14% | — | IBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) FirmwareIBM Power System S914 (9009-41g) FirmwareIBM Power System S924 (9009-42g) Firmware+6 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service… | |
| Analizada | Alta (8.1) | 0.15% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the BMC/FSP can… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP… | |
| Pendiente de análisis | Alta (7.4) | 0.47% | — | Openshift ConsoleAIOpenshift HelmAI | 11/8/2026 | 21/9/2026 | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and… | |
| Pendiente de análisis | Alta (7.4) | 0.47% | — | Openshift ConsoleAI | 11/8/2026 | 21/9/2026 | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position. | |
| Pendiente de análisis | Baja (3.7) | 0.19% | — | SAP Data Services Management ConsoleAI | 11/8/2026 | 26/8/2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within… | |
| Pendiente de análisis | Crítica (9.5) | 0.32% | — | Veeam Service Provider ConsoleAI | 4/8/2026 | 3/9/2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | |
| Pendiente de análisis | Crítica (9) | 0.53% | — | Veeam Service Provider ConsoleAI | 4/8/2026 | 3/9/2026 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Veeam Service Provider ConsoleAI | 4/8/2026 | 3/9/2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | |
| Pendiente de análisis | Alta (8.7) | 0.45% | — | Veeam Service Provider ConsoleAI | 4/8/2026 | 3/9/2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | |
| Analizada | Crítica (9.8) | 0.76% | — | IBM Hardware Management Console | 30/7/2026 | 10/8/2026 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Veeam Service Provider ConsoleAI | 30/7/2026 | 3/9/2026 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an… | |
| Aplazada | Crítica (9) | 0.49% | — | Rustfs ConsoleAI | 15/7/2026 | 16/7/2026 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the… | |
| Aplazada | Crítica (9.4) | 0.16% | — | XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI | 9/7/2026 | 29/9/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,… | |
| Aplazada | Crítica (9.4) | 0.16% | — | Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI | 9/7/2026 | 29/9/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,… | |
| Aplazada | Crítica (9.4) | 0.16% | — | XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI | 9/7/2026 | 29/9/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: | |
| Aplazada | Media (5.1) | 0.27% | — | Capgo ConsoleAI | 30/6/2026 | 1/7/2026 | Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs. |