Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.32% | — | IBM Analytics Content HUB | 10/7/2025 | 17/6/2026 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cognos Analytics | 28/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Aplazada | Media (5.3) | 0.25% | — | Afsanalytics AFS AnalyticsAI | 17/6/2025 | 17/6/2026 | Missing Authorization vulnerability in AFS Analytics AFS Analytics addfreestats allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AFS Analytics: from n/a through <= 4.21. | |
| Analizada | Alta (7.5) | 0.46% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files. | |
| Analizada | Crítica (9.8) | 0.33% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect… | |
| Analizada | Crítica (9.1) | 0.26% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device. | |
| Analizada | Media (6.1) | 0.31% | — | Sick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic AnalyticsSick Media Server+2 | 12/6/2025 | 17/6/2026 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). | |
| Analizada | Media (6.1) | 0.33% | — | Sick Field AnalyticsSick Media Server | 12/6/2025 | 17/6/2026 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while… | |
| Analizada | Media (6.1) | 0.35% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards… | |
| Analizada | Media (5.8) | 0.34% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports. | |
| Analizada | Alta (7.5) | 0.44% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering. | |
| Analizada | Media (5.3) | 0.41% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Media (6.5) | 0.37% | — | Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | |
| Analizada | Media (5.4) | 0.29% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source. | |
| Analizada | Alta (7.5) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources. | |
| Analizada | Media (5.3) | 0.28% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system. | |
| Analizada | Media (4.8) | 0.21% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Analizada | Alta (8.8) | 0.25% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (6.5) | 0.46% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction. | |
| Analizada | Media (5.4) | 0.20% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.5) | 0.33% | — | Cisco Secure Network Analytics | 21/5/2025 | 17/6/2026 | A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms and alerts on an affected product. Thi vulnerability is due… | |
| Analizada | Alta (7.2) | 0.58% | — | Cisco Secure Network Analytics | 21/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. | |
| Aplazada | Media (6.1) | 0.34% | — | Affiliate Sales IN Google Analytics AND Other ToolsAI | 21/5/2025 | 17/6/2026 | The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for unauthenticated attackers to redirect… |