Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.33%—IBM Urbancode Deploy8/7/201617/6/2026
The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors.
ModificadaMedia (5.9)1.2%—IBM Urbancode Deploy1/7/201617/6/2026
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.
ModificadaMedia (4.3)0.85%—IBM Urbancode Deploy1/7/201617/6/2026
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
ModificadaAlta (7.7)1.0%—IBM Urbancode Deploy29/6/201617/6/2026
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
ModificadaMedia (6.5)1.4%—Cisco Prime Collaboration Deployment23/6/201617/6/2026
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.
ModificadaAlta (7.5)4.0%—HP Insight Control Server Deployment8/6/201617/6/2026
HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.
ModificadaAlta (8.4)0.66%—HP Insight Control Server Deployment8/6/201617/6/2026
HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.
ModificadaMedia (6.1)1.8%—HP Insight Control Server Deployment8/6/201617/6/2026
HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.
ModificadaAlta (8.1)2.1%—HP Insight Control Server Deployment8/6/201617/6/2026
HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
ModificadaMedia (5.4)0.62%—IBM Urbancode Deploy1/1/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6)1.5%—IBM Urbancode Deploy6/10/201517/6/2026
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
ModificadaMedia (6.8)3.4%—Symantec Deployment SolutionSymantec Ghost Solutions Suite20/9/201517/6/2026
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of…
ModificadaAlta (7.5)3.5%—Tibco Spotfire Deployment KITTibco Spotfire ProfessionalTibco Spotfire WEB PlayerTibco Spotfire Desktop+521/7/201517/6/2026
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3,…
ModificadaBaja (2.1)0.38%—Ceph-deploy16/6/201517/6/2026
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.
ModificadaBaja (2.1)0.39%—Ceph-deploy8/6/201517/6/2026
The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.
ModificadaMedia (5)1.2%—IBM Workload Deployer25/5/201517/6/2026
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.
ModificadaMedia (4.3)1.6%—HP Insight Control Server Deployment15/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9)3.7%—IBM Pureapplication SystemIBM Workload Deployer10/1/201517/6/2026
Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3)…
ModificadaAlta (7.2)1.2%💥 ExploitSymantec Deployment Solution22/12/201417/6/2026
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.
ModificadaMedia (4)0.94%—Tibco Silver Fabric EnablerTibco Spotfire Deployment KITTibco Spotfire WEB Player21/11/201417/6/2026
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
ModificadaMedia (4)1.1%—IBM Urbancode Deploy10/9/201417/6/2026
IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.
ModificadaMedia (5)1.7%—SAP Software Deployment Manager10/4/201417/6/2026
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
ModificadaAlta (7.5)3.1%—Tibco WEB PlayerTibco Automation ServicesTibco Spotfire ServerTibco Spotfire Professional+310/4/201417/6/2026
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before…