Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1305 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.32%—IBM Analytics Content HUB10/7/202517/6/2026
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
AnalizadaMedia (5.4)0.20%—IBM Cognos Analytics28/6/202517/6/2026
IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
AplazadaMedia (5.3)0.25%—Afsanalytics AFS AnalyticsAI17/6/202517/6/2026
Missing Authorization vulnerability in AFS Analytics AFS Analytics addfreestats allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AFS Analytics: from n/a through <= 4.21.
AnalizadaAlta (7.5)0.46%—Sick Field Analytics12/6/202517/6/2026
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.
AnalizadaCrítica (9.8)0.33%—Sick Field Analytics12/6/202517/6/2026
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect…
AnalizadaCrítica (9.1)0.26%—Sick Field Analytics12/6/202517/6/2026
A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.
AnalizadaMedia (6.1)0.31%—Sick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic AnalyticsSick Media Server+212/6/202517/6/2026
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).
AnalizadaMedia (6.1)0.33%—Sick Field AnalyticsSick Media Server12/6/202517/6/2026
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while…
AnalizadaMedia (6.1)0.35%—Sick Field Analytics12/6/202517/6/2026
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards…
AnalizadaMedia (5.8)0.34%—Sick Field Analytics12/6/202517/6/2026
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
AnalizadaAlta (7.5)0.44%—Sick Field Analytics12/6/202517/6/2026
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
AnalizadaMedia (5.3)0.41%—Sick Field Analytics12/6/202517/6/2026
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
AnalizadaMedia (6.5)0.37%—Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+212/6/202517/6/2026
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
AnalizadaMedia (5.4)0.29%—Sick Field Analytics12/6/202517/6/2026
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source.
AnalizadaAlta (7.5)0.49%—Sick Baggage AnalyticsSick Enterprise AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+212/6/202517/6/2026
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.
AnalizadaAlta (7.5)0.40%—IBM Cognos Analytics11/6/202517/6/2026
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.
AnalizadaMedia (5.3)0.28%—IBM Cognos Analytics11/6/202517/6/2026
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
AnalizadaMedia (4.8)0.21%—IBM Cognos Analytics11/6/202517/6/2026
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
AnalizadaAlta (8.8)0.25%—IBM Planning Analytics Local1/6/202517/6/2026
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
AnalizadaMedia (6.5)0.46%—IBM Planning Analytics Local1/6/202517/6/2026
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.
AnalizadaMedia (5.4)0.20%—IBM Planning Analytics Local1/6/202517/6/2026
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.21%—IBM Planning Analytics Local1/6/202517/6/2026
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (6.5)0.33%—Cisco Secure Network Analytics21/5/202517/6/2026
A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms and alerts on an affected product. Thi vulnerability is due…
AnalizadaAlta (7.2)0.58%—Cisco Secure Network Analytics21/5/202517/6/2026
A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.
AplazadaMedia (6.1)0.34%—Affiliate Sales IN Google Analytics AND Other ToolsAI21/5/202517/6/2026
The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for unauthenticated attackers to redirect…