Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.9%—IBM Integration BUSIBM Websphere Message Broker11/1/201617/6/2026
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.
ModificadaBaja (3.2)0.33%—IBM Websphere Message BrokerIBM Integration BUS26/10/201517/6/2026
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
ModificadaBaja (3.5)2.4%💥 ExploitMedhabidotcom MDC Private Message2/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.
ModificadaBaja (3.5)0.87%—IBM Integration BUSIBM Websphere Message Broker23/8/201517/6/2026
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)1.1%—IBM Websphere Message BrokerIBM Integration BUS28/6/201517/6/2026
IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection…
ModificadaMedia (5)1.4%—IBM Integration BUSIBM Websphere Message Broker2/2/201517/6/2026
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
ModificadaMedia (5.4)0.27%—Ienvisage Pakistan Cricket News21/10/201417/6/2026
The Pakistan Cricket News (aka com.conduit.app_cf18df8bdf454eb0a836e2d29886bc40.app) application 1.21.38.6504 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Kellygerards Mr.sausage19/10/201417/6/2026
The Mr.Sausage (aka com.app_mrsausage.layout) application 1.301 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—7sage Lsat Prep - Proctor25/9/201417/6/2026
The 7Sage LSAT Prep - Proctor (aka com.sevensage.lsat) application 2.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Insta.me Instamessage - Instagram Chat23/9/201417/6/2026
The InstaMessage - Instagram Chat (aka com.futurebits.instamessage.free) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4)1.1%—IBM Websphere Message BrokerIBM Integration BUS18/9/201417/6/2026
The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.
ModificadaAlta (7.1)2.0%—Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF15/8/201417/6/2026
Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials.
ModificadaAlta (9.3)2.8%—Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF15/8/201417/6/2026
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.
ModificadaMedia (4.3)2.1%—Woocommerce Sagepay Direct Payment Gateway Project Woocommerce Sagepay Direct Payment Gateway2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter.
ModificadaBaja (3.5)2.4%💥 ExploitAmtelco Misecuremessages6/5/201417/6/2026
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
ModificadaMedia (4.6)1.1%—IBM Messagesight JMS ClientIBM Messagesight15/4/201417/6/2026
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.
ModificadaMedia (4.3)1.4%—IBM Messagesight JMS ClientIBM Messagesight15/4/201417/6/2026
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.
ModificadaMedia (4.3)1.3%—IBM Messagesight JMS ClientIBM Messagesight15/4/201417/6/2026
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.
ModificadaMedia (4.3)1.3%—IBM Messagesight JMS ClientIBM Messagesight15/4/201417/6/2026
The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.
ModificadaMedia (5)1.8%—Amtelco Misecuremessages15/4/201417/6/2026
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.
ModificadaMedia (5)1.4%—Schneider-electric Telvent Sage 3030 Firmware31/1/201417/6/2026
The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic.
ModificadaAlta (7.5)1.2%💥 ExploitBrian Cabunac Browser TO Email Phone Message System16/1/201416/6/2026
SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
ModificadaMedia (4.3)2.8%—IBM Websphere Message Broker19/10/201316/6/2026
The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.
ModificadaMedia (4.3)1.3%—Alcatel-lucent Omnitouch 8400 Instant Communications SuiteAlcatel-lucent Omnitouch 8460 Advanced Communication ServerAlcatel-lucent Omnitouch 8660 MY TeamworkAlcatel-lucent Omnitouch 8670 Automated Delivery Message Delivery System20/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant…
ModificadaAlta (9.3)4.2%—Sagelighteditor Sagelight9/8/201316/6/2026
Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow.