Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.85% | — | IBM Netezza Performance Portal | 26/3/2014 | 17/6/2026 | The (1) ssl.conf and (2) httpd.conf files in the Apache HTTP Server component in IBM Netezza Performance Portal 2.0 before 2.0.0.4 have weak SSLCipherSuite values, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. | |
| Modificada | Media (4) | 0.84% | — | IBM Netezza Performance Portal | 26/2/2014 | 17/6/2026 | IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an HTTP POST request. | |
| Modificada | Media (5) | 1.4% | — | IBM Rational Performance TesterIBM Rational Service Tester | 22/11/2013 | 17/6/2026 | Unspecified vulnerability in IBM Rational Service Tester 8.3.x and 8.5.x before 8.5.1 and Rational Performance Tester 8.3.x and 8.5.x before 8.5.1 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Baja (1.9) | 0.48% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network. | |
| Modificada | Baja (3.5) | 0.92% | — | IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager | 25/9/2013 | 16/6/2026 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown… | |
| Modificada | Media (5) | 1.9% | — | Capasystems Performance Guard | 12/9/2013 | 16/6/2026 | Directory traversal vulnerability in logreader/uploadreader.jsp in CapaSystems Performance Guard before 6.2.102 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4) | 1.4% | — | IBM Infosphere Optim Performance ManagerIBM Optim Performance Manager | 22/8/2013 | 16/6/2026 | Directory traversal vulnerability in IBM Optim Performance Manager 4.1.1 and IBM InfoSphere Optim Performance Manager 5.x before 5.2 allows remote authenticated users to read arbitrary files via a crafted URL. | |
| Modificada | Alta (7.1) | 3.1% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 10% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Media (4) | 0.94% | — | IBM Netezza Performance Portal | 5/4/2013 | 16/6/2026 | HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files. | |
| Modificada | Baja (2.1) | 0.37% | — | SGI Performance Co-pilot | 29/11/2012 | 16/6/2026 | The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file. | |
| Modificada | Alta (10) | 4.4% | — | HP Performance Insight | 7/11/2012 | 16/6/2026 | Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3269. | |
| Modificada | Alta (7.5) | 2.8% | — | HP Performance Insight | 7/11/2012 | 16/6/2026 | Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270. | |
| Modificada | Media (4.3) | 7.2% | 💥 Exploit | Solarwinds IP Address Manager WEB InterfaceSolarwinds Orion Network Performance Monitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field. | |
| Modificada | Media (5) | 3.3% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw." | |
| Modificada | Media (5) | 2.4% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in… | |
| Modificada | Media (5) | 1.8% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments. | |
| Modificada | Media (5) | 5.7% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the… | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Solarwinds Orion Network Performance Monitor | 12/8/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or… | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Solarwinds Orion Network Performance Monitor | 12/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file. | |
| Modificada | Alta (7.8) | 2.2% | — | Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco CRS Performance Route Processor | 31/5/2012 | 16/6/2026 | Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593. | |
| Modificada | Alta (9) | 2.3% | — | HP Performance Insight | 9/5/2012 | 16/6/2026 | Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Media (4.3) | 1.9% | — | HP Performance Insight | 9/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.3% | — | HP Performance Insight | 9/5/2012 | 16/6/2026 | SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |