Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.55% | — | IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Flashcopy Manager FOR Vmware | 15/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545. | |
| Modificada | Media (6.5) | 0.33% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user. | |
| Modificada | Media (6.8) | 1.00% | — | IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 1/2/2017 | 17/6/2026 | IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges. | |
| Modificada | Alta (8.5) | 0.96% | — | IBM Tivoli Storage Manager FOR Virtual Environments | 25/11/2016 | 17/6/2026 | IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins. | |
| Modificada | Crítica (10) | 3.9% | — | IBM Tivoli Storage Flashcopy Manager FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 21/2/2016 | 17/6/2026 | The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect… | |
| Modificada | Crítica (10) | 2.5% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote… | |
| Modificada | Alta (8.5) | 0.98% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote… | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Tivoli Storage Flashcopy ManagerIBM Tivoli Storage Manager FOR Virtual Environments | 4/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.3.0 allows remote… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Media (4.1) | 0.26% | — | IBM Tivoli Storage Manager FOR Virtual Environments | 26/5/2014 | 17/6/2026 | The Data Protection for VMware component in IBM Tivoli Storage Manager for Virtual Environments (TSMVE) 6.3 through 7.1.0.2 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (disk consumption) via unspecified GUI… |