Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Umbraengineering PS | 7/9/2018 | 17/6/2026 | A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 20/8/2018 | 17/6/2026 | Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425. | |
| Modificada | Media (5.4) | 0.85% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 20/8/2018 | 17/6/2026 | Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655. | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Media (6.8) | 0.36% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 10/7/2018 | 17/6/2026 | IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 10/7/2018 | 17/6/2026 | IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026. | |
| Modificada | Media (4.3) | 0.89% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719. | |
| Modificada | Media (5.3) | 1.2% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355. | |
| Modificada | Crítica (9.8) | 1.4% | — | Umbraengineering Merge-recursive | 3/7/2018 | 17/6/2026 | The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. | |
| Modificada | Crítica (9.8) | 2.5% | — | IBM Engineering Requirements Management Doors | 27/6/2018 | 17/6/2026 | An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208. | |
| Modificada | Media (4.3) | 0.95% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 24/4/2018 | 17/6/2026 | IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational… | |
| Modificada | Media (4.3) | 0.95% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 24/4/2018 | 17/6/2026 | IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 24/4/2018 | 17/6/2026 | IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational… | |
| Modificada | Media (5.4) | 0.93% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 23/3/2018 | 17/6/2026 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.93% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 23/3/2018 | 17/6/2026 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.93% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 23/3/2018 | 17/6/2026 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 23/3/2018 | 17/6/2026 | IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 23/3/2018 | 17/6/2026 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970. | |
| Modificada | Baja (3.3) | 0.13% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 20/3/2018 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert… | |
| Modificada | Media (4.8) | 0.63% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7… | |
| Modificada | Media (6.1) | 0.85% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7… | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x… | |
| Modificada | Media (6.7) | 0.35% | — | IBM Engineering Lifecycle Optimization - Publishing | 2/3/2018 | 17/6/2026 | IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022. |