Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.94% | — | IBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Media (5.4) | 0.80% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team Concert | 12/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (3.3) | 0.30% | — | Moxa Oncell G3001 FirmwareMoxa Oncell G3100v2 Firmware | 24/8/2016 | 17/6/2026 | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file. | |
| Modificada | Crítica (9.8) | 4.0% | — | Moxa Oncell G3001 FirmwareMoxa Oncell G3100v2 Firmware | 24/8/2016 | 17/6/2026 | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Rational Team ConcertIBM Rational Collaborative Lifecycle Management | 15/7/2016 | 17/6/2026 | The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request. | |
| Modificada | Media (5.4) | 1.2% | — | HP Storeonce Backup System Software | 5/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.5% | — | HP Storeonce Backup System Software | 5/1/2016 | 17/6/2026 | HP StoreOnce Backup system software before 3.13.1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.3% | — | HP Storeonce Backup System Software | 5/1/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Baja (3.5) | 0.45% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 3/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x… | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management+4 | 3/1/2016 | 17/6/2026 | Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1;… | |
| Modificada | Media (4.3) | 0.55% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Software Architect Design Manager+4 | 3/1/2016 | 17/6/2026 | Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC)… | |
| Modificada | Media (6.8) | 1.2% | — | IBM Rational Quality ManagerIBM Rational Rhapsody Design ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 2/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert… | |
| Modificada | Alta (8.3) | 1.7% | — | Moxa Oncell Central Manager | 21/12/2015 | 17/6/2026 | The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session. | |
| Modificada | Alta (8.3) | 1.8% | — | Moxa Oncell Central Manager | 21/12/2015 | 17/6/2026 | The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action. | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Rational Doors Next GenerationIBM Rational Team ConcertIBM Rational Collaborative Lifecycle ManagementIBM Rational Requirements Composer+1 | 20/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x… | |
| Modificada | Media (4) | 1.0% | — | IBM Rational Requirements ComposerIBM Rhapsody Design ManagerIBM Rational Team ConcertIBM Rational Quality Manager+4 | 7/6/2015 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x… | |
| Modificada | Media (5) | 1.2% | — | IBM Rational Software Architect Design ManagerIBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Collaborative Lifecycle Management+4 | 27/4/2015 | 17/6/2026 | The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7… | |
| Modificada | Media (4) | 1.3% | — | IBM Rational Doors Next GenerationIBM Rational Requirements ComposerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5.5) | 1.4% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Rational Team Concert | 13/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0122. | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Rational Team Concert | 13/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0123. | |
| Modificada | Media (5.4) | 0.27% | — | Mobileticketapp Ticket APP - Concerts & Sports | 18/9/2014 | 17/6/2026 | The TICKET APP - Concerts & Sports (aka com.xcr.android.ticketapp) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.7% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+3 | 12/9/2014 | 17/6/2026 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to… | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Rational Team Concert | 29/7/2014 | 17/6/2026 | IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors. |