Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.83% | — | Nextcloud Circles | 4/2/2020 | 17/6/2026 | Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle. | |
| Modificada | Crítica (9.1) | 2.1% | — | IBM Smartcloud Analytics LOG Analysis | 10/12/2019 | 17/6/2026 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518. | |
| Modificada | Media (4.4) | 0.31% | — | IBM Smartcloud Analytics LOG Analysis | 22/11/2019 | 17/6/2026 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml and could allow an attacker to perform disruptive administrator tasks. IBM X-Force ID: 159517. | |
| Modificada | Media (4.6) | 0.61% | — | IBM Smartcloud Analytics LOG Analysis | 22/11/2019 | 17/6/2026 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187. | |
| Modificada | Media (6.1) | 0.90% | — | IBM Smartcloud Analytics LOG Analysis | 22/11/2019 | 17/6/2026 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.… | |
| Modificada | Baja (3.7) | 0.48% | — | IBM Smartcloud Analytics LOG Analysis | 22/11/2019 | 17/6/2026 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+5 | 24/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 9/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. | |
| Modificada | Crítica (9.8) | 1.8% | — | Nextcloud Lookup-server | 7/8/2019 | 17/6/2026 | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands. | |
| Modificada | Crítica (9.8) | 2.1% | — | TCL Alcatel Linkzone Firmware | 2/8/2019 | 17/6/2026 | The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password. | |
| Modificada | Media (6.8) | 0.46% | — | Nextcloud | 30/7/2019 | 17/6/2026 | Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Nextcloud | 30/7/2019 | 17/6/2026 | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account. | |
| Modificada | Media (6.1) | 0.47% | — | Nextcloud | 30/7/2019 | 17/6/2026 | Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | |
| Modificada | Baja (2.4) | 0.43% | — | Nextcloud | 30/7/2019 | 17/6/2026 | Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved. | |
| Modificada | Media (4.6) | 0.39% | — | Nextcloud Server | 30/7/2019 | 17/6/2026 | Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time. | |
| Modificada | Media (6.8) | 0.50% | — | Nextcloud | 30/7/2019 | 17/6/2026 | Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML. | |
| Modificada | Media (4.3) | 0.85% | — | Nextcloud Server | 30/7/2019 | 17/6/2026 | A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. | |
| Modificada | Alta (8) | 2.6% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. | |
| Modificada | Media (5.4) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949. | |
| Modificada | Media (4.3) | 0.85% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. | |
| Modificada | Media (6.5) | 0.77% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. | |
| Modificada | Alta (8.8) | 2.5% | — | Nextcloud Extract | 5/6/2019 | 17/6/2026 | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters). | |
| Modificada | Alta (8.1) | 2.5% | — | Webroot Brightcloud | 3/1/2019 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this… | |
| Modificada | Alta (8.1) | 0.73% | — | Webroot Brightcloud | 18/12/2018 | 17/6/2026 | An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this… |