Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | IBM Security Secret Server | 4/8/2020 | 17/6/2026 | IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395. | |
| Modificada | Media (5.9) | 1.2% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 179988. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized user. IBM X-Force ID: 178182. | |
| Modificada | Media (5.3) | 1.4% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178181. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 177599. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 177514. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Security Secret Server | 24/6/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force… | |
| Modificada | Crítica (9.8) | 0.52% | — | IBM Security Secret Server | 19/2/2020 | 17/6/2026 | IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045. | |
| Modificada | Baja (3.7) | 0.79% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044. | |
| Modificada | Media (4.3) | 0.74% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043. | |
| Modificada | Baja (2.7) | 0.80% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013. | |
| Modificada | Baja (2.7) | 0.94% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170004. | |
| Modificada | Media (6.1) | 0.78% | — | IBM Security Secret Server | 28/1/2020 | 17/6/2026 | IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would… | |
| Modificada | Media (6.1) | 0.78% | — | Thycotic Secret Server | 23/10/2019 | 17/6/2026 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2). | |
| Modificada | Media (6.1) | 0.79% | — | Thycotic Secret Server | 23/10/2019 | 17/6/2026 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2). | |
| Modificada | Crítica (9.8) | 1.5% | — | Thycotic Secret Server | 23/10/2019 | 17/6/2026 | An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. | |
| Modificada | Crítica (9.8) | 1.2% | — | Thycotic Secret Server | 9/3/2018 | 17/6/2026 | The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended. | |
| Modificada | Media (5.4) | 0.57% | — | Thycotic Secret Server | 29/7/2017 | 17/6/2026 | The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections. | |
| Modificada | Baja (3.5) | 2.0% | 💥 Exploit | Thycotic Secret Server | 2/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handled when toggling the password mask. | |
| Modificada | Media (5.8) | 0.59% | — | Thycotic Secret Server | 2/6/2015 | 17/6/2026 | The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |