Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (1.9)0.48%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an…
ModificadaMedia (4.3)1.1%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
ModificadaBaja (3.5)0.92%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown…
ModificadaAlta (7.5)1.5%—Verifone Vericentre WEB Console15/11/201216/6/2026
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
ModificadaMedia (4.3)1.7%—SUN Java WEB ConsoleSUN Solaris1/7/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.9%—SUN Java WEB ConsoleSUN SolarisSunos12/12/200816/6/2026
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
ModificadaAlta (7.8)2.6%—SUN Java WEB Console11/3/200816/6/2026
Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.
ModificadaAlta (7.5)4.6%—SUN Java WEB ConsoleSUN Solaris19/4/200716/6/2026
Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.
ModificadaMedia (5)1.6%—HP Secure WEB Console1/11/199916/6/2026
HP Secure Web Console uses weak encryption.