Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.33% | — | IBM Urbancode Deploy | 8/7/2016 | 17/6/2026 | The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors. | |
| Modificada | Media (5.9) | 1.2% | — | IBM Urbancode Deploy | 1/7/2016 | 17/6/2026 | IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors. | |
| Modificada | Media (4.3) | 0.85% | — | IBM Urbancode Deploy | 1/7/2016 | 17/6/2026 | IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters. | |
| Modificada | Alta (7.7) | 1.0% | — | IBM Urbancode Deploy | 29/6/2016 | 17/6/2026 | IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Prime Collaboration Deployment | 23/6/2016 | 17/6/2026 | SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549. | |
| Modificada | Alta (7.5) | 4.0% | — | HP Insight Control Server Deployment | 8/6/2016 | 17/6/2026 | HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8.4) | 0.66% | — | HP Insight Control Server Deployment | 8/6/2016 | 17/6/2026 | HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (6.1) | 1.8% | — | HP Insight Control Server Deployment | 8/6/2016 | 17/6/2026 | HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors. | |
| Modificada | Alta (8.1) | 2.1% | — | HP Insight Control Server Deployment | 8/6/2016 | 17/6/2026 | HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Media (5.4) | 0.62% | — | IBM Urbancode Deploy | 1/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6) | 1.5% | — | IBM Urbancode Deploy | 6/10/2015 | 17/6/2026 | IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process. | |
| Modificada | Media (6.8) | 3.4% | — | Symantec Deployment SolutionSymantec Ghost Solutions Suite | 20/9/2015 | 17/6/2026 | ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of… | |
| Modificada | Alta (7.5) | 3.5% | — | Tibco Spotfire Deployment KITTibco Spotfire ProfessionalTibco Spotfire WEB PlayerTibco Spotfire Desktop+5 | 21/7/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3,… | |
| Modificada | Baja (2.1) | 0.38% | — | Ceph-deploy | 16/6/2015 | 17/6/2026 | ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Baja (2.1) | 0.39% | — | Ceph-deploy | 8/6/2015 | 17/6/2026 | The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (5) | 1.2% | — | IBM Workload Deployer | 25/5/2015 | 17/6/2026 | The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document. | |
| Modificada | Media (4.3) | 1.6% | — | HP Insight Control Server Deployment | 15/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9) | 3.7% | — | IBM Pureapplication SystemIBM Workload Deployer | 10/1/2015 | 17/6/2026 | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3)… | |
| Modificada | Alta (7.2) | 1.2% | 💥 Exploit | Symantec Deployment Solution | 22/12/2014 | 17/6/2026 | Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4) | 0.94% | — | Tibco Silver Fabric EnablerTibco Spotfire Deployment KITTibco Spotfire WEB Player | 21/11/2014 | 17/6/2026 | Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Media (4) | 1.1% | — | IBM Urbancode Deploy | 10/9/2014 | 17/6/2026 | IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page. | |
| Modificada | Media (5) | 1.7% | — | SAP Software Deployment Manager | 10/4/2014 | 17/6/2026 | The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications. | |
| Modificada | Alta (7.5) | 3.1% | — | Tibco WEB PlayerTibco Automation ServicesTibco Spotfire ServerTibco Spotfire Professional+3 | 10/4/2014 | 17/6/2026 | Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before… |