Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | CA Spectrum | 1/5/2018 | 17/6/2026 | CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Alta (8.1) | 0.91% | — | IBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 4/4/2018 | 17/6/2026 | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new… | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Spectrum ScaleIBM General Parallel File System | 2/3/2018 | 17/6/2026 | IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378. | |
| Modificada | Alta (7.5) | 1.4% | — | Spectrum Tc8717t Firmware | 31/7/2017 | 17/6/2026 | The Time Warner firmware on Technicolor TC8717T devices sets the default Wi-Fi passphrase to a combination of the SSID and BSSID, which makes it easier for remote attackers to obtain network access by reading a beacon frame. | |
| Modificada | Alta (8.8) | 0.33% | — | IBM Spectrum LSF | 14/4/2017 | 17/6/2026 | IBM Platform LSF 10.1 contains an unspecified vulnerability that could allow a local user to escalate their privileges and obtain root access. IBM X-Force ID: 123741. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Seawell Networks Spectrum SDC | 13/4/2017 | 17/6/2026 | SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions. | |
| Modificada | Media (6.5) | 6.8% | 💥 Exploit | Seawell Networks Spectrum SDC | 13/4/2017 | 17/6/2026 | Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00. | |
| Modificada | Crítica (9.8) | 6.6% | 💥 Exploit | Seawell Networks Spectrum SDC | 13/4/2017 | 17/6/2026 | SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. | |
| Modificada | Alta (7.2) | 4.0% | — | IBM General Parallel File SystemIBM Spectrum Scale | 1/2/2017 | 17/6/2026 | IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Baja (3.1) | 0.49% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server. | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Modificada | Alta (7) | 0.30% | — | IBM Spectrum ScaleIBM General Parallel File System | 25/11/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program. | |
| Modificada | Alta (7) | 0.30% | — | IBM Spectrum ScaleIBM General Parallel File System | 25/11/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program. | |
| Modificada | Media (5.7) | 0.85% | — | IBM Tivoli Storage Productivity CenterIBM Spectrum Control | 26/9/2016 | 17/6/2026 | IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site. | |
| Modificada | Media (6.5) | 1.6% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 26/9/2016 | 17/6/2026 | Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 26/9/2016 | 17/6/2026 | IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request. | |
| Modificada | Media (5.4) | 0.82% | — | IBM Spectrum ControlIBM Tivoli Storage Productivity Center | 26/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string. | |
| Modificada | Media (5.4) | 0.86% | — | IBM Spectrum Control | 26/9/2016 | 17/6/2026 | IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors. | |
| Modificada | Alta (7) | 0.32% | — | IBM General Parallel File System Storage ServerIBM Spectrum Scale | 29/6/2016 | 17/6/2026 | IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command. | |
| Modificada | Media (5.9) | 0.38% | — | IBM Spectrum Scale | 27/1/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors. | |
| Modificada | Crítica (10) | 2.5% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote… | |
| Modificada | Media (4) | 0.36% | — | IBM General Parallel File SystemIBM Spectrum Scale | 2/1/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors. | |
| Modificada | Alta (8.5) | 0.98% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Spectrum Scale | 1/1/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors. |