Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.75% | — | IBM Jazz Reporting Service | 8/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than… | |
| Modificada | Media (5.4) | 0.62% | — | IBM Jazz Reporting Service | 8/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than… | |
| Modificada | Alta (8.8) | 1.0% | — | IBM Jazz Reporting Service | 8/7/2016 | 17/6/2026 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation. | |
| Modificada | Media (6.5) | 0.88% | — | IBM Jazz Reporting Service | 8/7/2016 | 17/6/2026 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.62% | — | IBM Jazz Reporting Service | 8/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than… | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Jazz Reporting Service | 29/1/2016 | 17/6/2026 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder server outage) via a crafted request to a Report Builder instance URL. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Jazz Reporting Service | 17/1/2016 | 17/6/2026 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information. | |
| Modificada | Media (4.3) | 0.89% | — | IBM Jazz Reporting Service | 17/1/2016 | 17/6/2026 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role. | |
| Modificada | Media (4.3) | 0.89% | — | IBM Jazz Reporting Service | 17/1/2016 | 17/6/2026 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.62% | — | IBM Jazz Reporting Service | 17/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (3.1) | 0.81% | — | IBM Jazz Reporting Service | 10/1/2016 | 17/6/2026 | Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Jazz Reporting Service | 10/1/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | IBM Sterling B2B IntegratorIBM Sterling IntegratorIBM Tivoli Common ReportingIBM Watson Content Analytics+3 | 2/1/2016 | 17/6/2026 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library. | |
| Modificada | Baja (2.5) | 0.28% | — | IBM Tivoli Common Reporting | 2/1/2016 | 17/6/2026 | IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 preserves user permissions across group-add and group-remove operations,… | |
| Modificada | Baja (2.5) | 0.28% | — | IBM Tivoli Common Reporting | 2/1/2016 | 17/6/2026 | IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 allows local users to bypass the Cognos Application Firewall (CAF)… | |
| Analizada | Alta (7.8) | 5.0% | ⚠ Explotación activa💥 Exploit | Redhat Automatic BUG Reporting ToolOracle LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 7/12/2015 | 27/8/2026 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump. | |
| Modificada | Baja (3.6) | 0.90% | 💥 Exploit | Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 7/12/2015 | 17/6/2026 | The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp. | |
| Modificada | Baja (3.5) | 1.5% | — | IBM Tivoli Common Reporting | 4/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 1.4% | — | Intersectalliance System Intrusion Analysis AND Reporting Environment | 14/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command. | |
| Modificada | Alta (7.1) | 2.5% | — | Oracle Hyperion Interactive Reporting | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in the Hyperion Strategic Finance component in Oracle Hyperion 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server. | |
| Modificada | Media (6.9) | 0.31% | — | Redhat Automatic BUG Reporting Tool | 12/3/2013 | 16/6/2026 | abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes." | |
| Modificada | Baja (3.7) | 0.45% | — | Redhat Automatic BUG Reporting Tool | 12/3/2013 | 16/6/2026 | Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module. | |
| Modificada | Media (6.8) | 1.1% | — | Oracle Hyperion Interactive ReportingOracle Essbase ServerOracle Hyperion Production Reporting ServerOracle Integration Services Server | 21/12/2012 | 16/6/2026 | Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11.1.2.2, Production Reporting Server 11.1.2.1 and 11.1.2.2, and Integration Services Server 11.1.2.1 and 11.1.2.2 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 16% | — | Microsoft SQL ServerMicrosoft SQL Server Reporting Services | 9/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability." | |
| Modificada | Baja (1.9) | 0.44% | — | Redhat Automatic BUG Reporting Tool | 3/7/2012 | 16/6/2026 | The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information. |