Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.52% | — | IBM Security Verify Privilege On-premises | 16/4/2024 | 17/6/2026 | IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651. | |
| Analizada | Alta (7.5) | 0.42% | — | IBM Security Verify Privilege On-premises | 4/3/2024 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453. | |
| Modificada | Media (5.3) | 0.28% | — | Splicecom Maximiser Soft PBX | 25/1/2024 | 17/6/2026 | SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack. | |
| Modificada | Crítica (9.8) | 0.80% | — | Splicecom Maximiser Soft PBX | 25/1/2024 | 17/6/2026 | SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack. | |
| Modificada | Media (6.1) | 0.37% | — | Splicecom Maximiser Soft PBX | 25/1/2024 | 17/6/2026 | Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component. | |
| Modificada | Media (5.3) | 0.30% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455. | |
| Modificada | Media (5.3) | 0.68% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454. | |
| Modificada | Media (4.4) | 0.45% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634. | |
| Modificada | Media (5.3) | 0.52% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452. | |
| Modificada | Media (5.9) | 0.48% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221963. | |
| Modificada | Alta (7.5) | 0.41% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962. | |
| Modificada | Media (4.3) | 0.24% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957. | |
| Modificada | Alta (8.8) | 1.2% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. | |
| Modificada | Media (5.3) | 0.61% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899. | |
| Modificada | Alta (7.1) | 0.47% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898. | |
| Modificada | Media (4.3) | 0.44% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. | |
| Modificada | Media (4.3) | 0.44% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. | |
| Modificada | Media (5.3) | 0.48% | — | IBM Security Verify Privilege On-premises | 17/10/2023 | 17/6/2026 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827. | |
| Modificada | Media (6.1) | 1.2% | — | Structurizr On-premises Installation | 12/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194. | |
| Modificada | Media (6.5) | 0.53% | — | Sysaid On-premises | 30/7/2023 | 17/6/2026 | Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method. | |
| Modificada | Alta (7.2) | 0.65% | — | Sysaid On-premises | 30/7/2023 | 17/6/2026 | Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method. | |
| Modificada | Alta (7.5) | 1.8% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | |
| Modificada | Crítica (9.8) | 0.92% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data… | |
| Modificada | Media (6.5) | 0.74% | — | Zoom On-premise Meeting Connector MMR | 14/10/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions. | |
| Modificada | Media (6.5) | 0.56% | — | Zoom On-premise Meeting Connector MMR | 14/10/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions. |