Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application Server | 18/12/2014 | 17/6/2026 | The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related… | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Application Server | 18/12/2014 | 17/6/2026 | IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process Server | 16/12/2014 | 17/6/2026 | IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for… | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 12/12/2014 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Websphere Portal | 11/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response. | |
| Modificada | Media (6) | 0.52% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (5) | 2.2% | — | IBM Operational Decision ManagerIBM Websphere Ilog JrulesIBM Websphere Operational Decision Management | 11/12/2014 | 17/6/2026 | The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Decision Management 7.5 before FP3 IF41; and Operational Decision Manager 8.0 before MP1 FP2 IF34, 8.5 before MP1 FP1 IF43, and 8.6 before IF8 allows remote attackers to read… | |
| Modificada | Baja (3.5) | 1.5% | — | IBM Websphere Portal | 26/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere Commerce | 5/11/2014 | 17/6/2026 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XML document containing a large number of nested entity… | |
| Modificada | Media (4) | 1.2% | — | IBM Websphere Commerce | 5/11/2014 | 17/6/2026 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Websphere Portal | 28/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.97% | — | IBM Websphere Portal | 28/10/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Portal | 28/10/2014 | 17/6/2026 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a… | |
| Modificada | Baja (3.5) | 1.6% | — | IBM Websphere Portal | 28/10/2014 | 17/6/2026 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity expansion, which allows remote authenticated users to cause a denial of service (memory and CPU consumption) via a… | |
| Modificada | Media (6.5) | 2.6% | — | IBM Websphere Portal | 28/10/2014 | 17/6/2026 | Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere MQ | 19/10/2014 | 17/6/2026 | The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration. | |
| Modificada | Baja (1.9) | 0.35% | — | IBM Websphere MQIBM Websphere MQ Explorer | 19/10/2014 | 17/6/2026 | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation. | |
| Modificada | Media (5) | 2.2% | — | IBM Websphere Application Server | 19/10/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method. | |
| Modificada | Media (4) | 1.6% | — | IBM Websphere Portal | 10/10/2014 | 17/6/2026 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Websphere MQ | 2/10/2014 | 17/6/2026 | IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors. | |
| Modificada | Alta (10) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 Appliance | 2/10/2014 | 17/6/2026 | Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie. | |
| Modificada | Alta (10) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 Appliance | 2/10/2014 | 17/6/2026 | Unspecified vulnerability in the Administrative Console on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network. | |
| Modificada | Media (6) | 1.0% | — | IBM Websphere Application Server | 23/9/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS… |