Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470. | |
| Modificada | Media (6.5) | 0.80% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126. | |
| Modificada | Alta (8.8) | 2.6% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+5 | 2/6/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with… | |
| Modificada | Alta (8.8) | 0.93% | — | Sipwise Next Generation Communication Platform | 23/4/2021 | 17/6/2026 | Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges. | |
| Modificada | Media (5.4) | 1.1% | — | Sipwise Next Generation Communication Platform | 23/4/2021 | 17/6/2026 | Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save… | |
| Modificada | Media (4.3) | 0.86% | — | Jenkins Warnings Next Generation | 18/3/2021 | 17/6/2026 | Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790. |