Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 1.0% | — | IBM Security Verify Information Queue | 11/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196076. | |
| Modificada | Media (4.4) | 0.35% | — | IBM Security Verify Privilege Manager | 8/1/2021 | 17/6/2026 | IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883. | |
| Modificada | Crítica (9.8) | 1.2% | — | IBM Security Access ManagerIBM Security Verify Access | 15/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216. | |
| Modificada | Media (6.1) | 0.92% | — | IBM Security Access ManagerIBM Security Verify Access | 15/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform… | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140. | |
| Modificada | Alta (7.8) | 0.30% | — | IBM Security Verify Privilege Vault Remote On-premises | 29/9/2020 | 17/6/2026 | IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Verify Gateway | 27/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server. IBM X-Force ID: 179476. | |
| Modificada | Media (5.9) | 0.65% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428. | |
| Modificada | Crítica (9.8) | 1.2% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 179266. | |
| Modificada | Alta (7.8) | 0.29% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009 | |
| Modificada | Baja (3.3) | 0.31% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008. | |
| Modificada | Media (5.5) | 0.21% | — | IBM Verify Gateway | 22/7/2020 | 17/6/2026 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004. | |
| Modificada | Media (4.3) | 1.2% | — | Soprano Fonecta Verify | 27/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Fonecta verify module 7.x-1.x before 7.x-1.6 for Drupal allows remote attackers from certain sources to inject arbitrary web script or HTML via unspecified vectors. |