Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Tivoli Netcool/omnibus GUI | 12/7/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204349. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Tivoli Netcool/omnibus GUI | 12/7/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204263. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Tivoli Netcool/omnibus GUI | 12/7/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204262. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Tivoli Netcool/omnibus GUI | 12/7/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204164. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus Webgui | 11/3/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 0.49% | — | IBM Tivoli Netcool/omnibus | 18/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174909. | |
| Modificada | Baja (2.4) | 0.34% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174908. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174907. | |
| Analizada | Media (5.5) | 0.41% | — | Libuser Project LibuserDebian LinuxFedoraproject FedoraRedhat Enterprise Linux | 25/11/2019 | 16/6/2026 | libuser has information disclosure when moving user's home directory | |
| Modificada | Media (6.3) | 0.28% | — | Libuser Project LibuserFedoraproject FedoraRedhat Enterprise Linux | 25/11/2019 | 16/6/2026 | libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. | |
| Modificada | Alta (7.1) | 0.36% | — | Ibus Project IbusRedhat Enterprise LinuxCanonical Ubuntu LinuxOracle ZFS Storage Appliance KIT | 25/11/2019 | 17/6/2026 | A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical… | |
| Modificada | Crítica (9.8) | 3.1% | — | Gitlab Omnibus | 16/9/2019 | 17/6/2026 | An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation | |
| Modificada | Crítica (9.8) | 4.7% | — | Deltacontrols Entelibus Firmware | 26/8/2019 | 17/6/2026 | Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.4% | — | Industrial.softing Fg-100 PB Profibus Firmware | 9/3/2018 | 17/6/2026 | Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Media (5.3) | 3.0% | — | LibimobiledeviceLibimobiledevice LibusbmuxdCanonical Ubuntu LinuxOpensuse Leap+1 | 13/6/2016 | 17/6/2026 | The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket. | |
| Modificada | Media (4.3) | 1.9% | — | Softing Fg-x00 Profibus Firmware | 31/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows remote attackers to inject arbitrary web script or HTML via the DEVICE_NAME parameter to cgi-bin/CFGhttp/. | |
| Modificada | Baja (2.1) | 5.3% | — | Redhat Libuser | 11/8/2015 | 17/6/2026 | Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field. | |
| Analizada | Alta (7.4) | 8.4% | ⚠ Explotación activa | Redhat Enterprise LinuxOpensuseLibuser Project Libuser | 11/8/2015 | 2/10/2026 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Tivoli Netcool/omnibus | 17/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Tivoli Netcool/omnibus | 1/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0941. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Tivoli Netcool/omnibus | 1/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942. | |
| Modificada | Baja (1.9) | 0.34% | — | Ibus Project IbusOpensuse | 23/11/2013 | 16/6/2026 | The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen. |