Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

982 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.
ModificadaAlta (7.1)1.4%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623.
ModificadaMedia (5.4)0.50%—IBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow Management+230/3/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.
ModificadaMedia (5.9)4.9%—NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+1430/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not…
ModificadaAlta (7.4)18%💥 PoCOpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+2925/3/202117/6/2026
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaMedia (5.9)19%—NettyNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationDebian Linux+49/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is…
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.
ModificadaMedia (5.4)0.73%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.
ModificadaMedia (5.4)0.60%—IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+54/3/202117/6/2026
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.
ModificadaAlta (7.5)37%—Nodejs Node.jsFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+93/3/202117/6/2026
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof…
ModificadaMedia (4.8)1.2%—Redhat UndertowNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation23/2/202117/6/2026
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain…
ModificadaMedia (5.9)7.4%💥 PoCOpensslDebian LinuxTenable Nessus Network MonitorTenable.sc+1916/2/202117/6/2026
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is…
ModificadaMedia (5.4)0.48%—IBM Business Automation WorkflowIBM Case Manager11/2/202117/6/2026
IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaAlta (7.5)3.9%—Apache ArtemisNetapp Oncommand Workflow Automation27/1/202117/6/2026
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.