Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.47% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Crítica (9.1) | 0.39% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Media (6.5) | 0.34% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem | |
| Analizada | Media (4.9) | 0.46% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files | |
| Analizada | Crítica (9.8) | 0.38% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system | |
| Analizada | Media (6.5) | 0.31% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability. | |
| Modificada | Media (6.5) | 0.46% | — | IBM Infosphere Master Data Management Server | 16/7/2021 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324. | |
| Modificada | Alta (7.5) | 1.9% | — | SAP Netweaver Master Data Management Server | 9/2/2021 | 17/6/2026 | Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal… | |
| Modificada | Media (5.4) | 0.72% | — | IBM Infosphere Master Data Management Server | 3/8/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.… | |
| Modificada | Media (5.7) | 1.2% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly… | |
| Modificada | Media (5.4) | 0.73% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited. | |
| Modificada | Alta (8.8) | 0.67% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Alta (8.8) | 0.56% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Infosphere Master Data Management Server | 19/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Infosphere Master Data Management Server | 2/6/2015 | 17/6/2026 | Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Infosphere Master Data Management Server | 25/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.3% | — | IBM Infosphere Master Data Management Server | 25/5/2015 | 17/6/2026 | The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Media (4) | 0.80% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaborative Server | 22/12/2014 | 17/6/2026 | The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's… | |
| Modificada | Media (5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain… | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors. |