Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.47%—Samsung Data Management Server Firmware29/7/202517/6/2026
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
AnalizadaCrítica (9.1)0.39%—Samsung Data Management Server Firmware29/7/202517/6/2026
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
AnalizadaMedia (6.5)0.34%—Samsung Data Management Server Firmware29/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem
AnalizadaMedia (4.9)0.46%—Samsung Data Management Server Firmware29/7/202517/6/2026
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
AnalizadaCrítica (9.8)0.38%—Samsung Data Management Server Firmware29/7/202517/6/2026
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
AnalizadaMedia (6.5)0.31%—Samsung Data Management Server Firmware29/7/202517/6/2026
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.
ModificadaMedia (6.5)0.46%—IBM Infosphere Master Data Management Server16/7/202117/6/2026
IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
ModificadaAlta (7.5)1.9%—SAP Netweaver Master Data Management Server9/2/202117/6/2026
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal…
ModificadaMedia (5.4)0.72%—IBM Infosphere Master Data Management Server3/8/201717/6/2026
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…
ModificadaMedia (5.7)1.2%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…
ModificadaMedia (5.4)0.73%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…
ModificadaMedia (6.5)1.1%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
ModificadaAlta (8.8)0.67%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.
ModificadaMedia (5.4)0.73%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…
ModificadaAlta (8.8)0.56%—IBM Infosphere Master Data Management Server31/7/201717/6/2026
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.
ModificadaAlta (7.8)0.23%—IBM Infosphere Master Data Management Server19/7/201717/6/2026
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
ModificadaMedia (6.5)1.1%—IBM Infosphere Master Data Management Server2/6/201517/6/2026
Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors.
ModificadaBaja (3.5)0.77%—IBM Infosphere Master Data Management Server25/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (5)1.3%—IBM Infosphere Master Data Management Server25/5/201517/6/2026
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in…
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management22/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote…
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management22/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote…
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management22/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote…
ModificadaMedia (4)0.80%—IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaborative Server22/12/201417/6/2026
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's…
ModificadaMedia (5)1.2%—IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management17/8/201417/6/2026
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain…
ModificadaAlta (7.5)1.2%—IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management17/8/201417/6/2026
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.