Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.4%—IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+118/3/201517/6/2026
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,…
ModificadaMedia (5)1.7%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+312/9/201417/6/2026
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…
ModificadaBaja (3.5)0.94%—IBM Rational Doors Next GenerationIBM Rational Requirements Composer4/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (4.9)0.95%—IBM Rational Requirements ComposerIBM Rational Doors Next Generation4/3/201417/6/2026
Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
ModificadaBaja (3.5)0.85%—IBM Rational Requirements ComposerIBM Rational Doors Next Generation4/3/201417/6/2026
Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.
ModificadaBaja (3.5)0.76%—IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Team Concert10/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary…
ModificadaMedia (5.4)0.43%—IBM Rational Requirements Composer12/9/201316/6/2026
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
ModificadaMedia (5.4)0.56%—IBM Rational Requirements Composer12/9/201316/6/2026
Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors.
ModificadaMedia (4.4)0.29%—IBM Rational Requirements Composer12/9/201316/6/2026
Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.
ModificadaMedia (4.9)0.85%—IBM Rational Requirements Composer12/9/201316/6/2026
Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
ModificadaMedia (6.9)0.42%—3DS 3dvia Composer7/9/201216/6/2026
Multiple untrusted search path vulnerabilities in 3DVIA Composer V6R2012 HF1 Build 6.8.1.1652 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) ibfs32.dll file in the current working directory, as demonstrated by a directory that contains a .smg file. NOTE: the provenance of this…
ModificadaAlta (10)62%💥 ExploitAvid Media Composer25/12/201116/6/2026
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.
ModificadaMedia (5)2.5%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.
ModificadaAlta (7.5)1.7%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.
ModificadaMedia (4.3)1.7%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp.
ModificadaAlta (7.5)2.9%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.
ModificadaMedia (6.8)3.2%—Apple Quartz Composer3/8/200716/6/2026
Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute arbitrary code via a crafted Quartz Composer file.
ModificadaMedia (5)2.4%—Arcsoft MMS Composer14/8/200616/6/2026
ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and possibly earlier, allow remote attackers to cause a denial of service (resource exhaustion and application crash) via WAPPush messages to UDP port UDP 2948.
ModificadaAlta (7.5)8.9%💥 ExploitArcsoft MMS Composer14/8/200616/6/2026
Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind,…
Orbitaley — Vulnerabilidades