Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.8% | — | IBM Content Navigator | 2/2/2021 | 17/6/2026 | IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Hide Thread Content Project Hide Thread Content | 28/1/2021 | 17/6/2026 | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit. | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance | 20/1/2021 | 17/6/2026 | A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain… | |
| Modificada | Media (6.4) | 1.3% | — | IBM Content Navigator | 21/12/2020 | 17/6/2026 | IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (5.4) | 0.86% | — | IBM Content Navigator | 10/11/2020 | 17/6/2026 | IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188737. | |
| Modificada | Media (5.4) | 0.86% | — | IBM Content Navigator | 10/11/2020 | 17/6/2026 | IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187189. | |
| Modificada | Alta (7.8) | 2.0% | — | IBM Filenet Content Manager | 9/11/2020 | 17/6/2026 | IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736. | |
| Modificada | Media (4.7) | 0.93% | — | Cisco Content Security Management ApplianceCisco WEB Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user… | |
| Modificada | Media (5.3) | 1.9% | — | Cisco Content Security Management ApplianceCisco AsyncosCisco Email Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices,… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Business Automation Content Analyzer ON Cloud | 21/9/2020 | 17/6/2026 | IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and… | |
| Modificada | Media (4.3) | 1.0% | — | IBM Content Navigator | 20/8/2020 | 17/6/2026 | IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679. | |
| Modificada | Baja (2.7) | 0.73% | — | IBM Content Navigator | 20/8/2020 | 17/6/2026 | IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316. | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Content Security Management ApplianceCisco Email Security Appliance | 17/8/2020 | 17/6/2026 | A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to excessive verbosity in certain… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Filenet Content Manager | 23/7/2020 | 17/6/2026 | IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181227. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Contentful Python Example | 21/5/2020 | 17/6/2026 | Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py. | |
| Modificada | Media (6.1) | 0.84% | — | Cisco Content Security Management Appliance | 6/5/2020 | 17/6/2026 | Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of the parameters of an HTTP request. An… | |
| Modificada | Media (5.3) | 1.3% | — | IBM Content Navigator | 24/3/2020 | 17/6/2026 | IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid in further attacks against the system. IBM X-Force ID: 177080. | |
| Modificada | Alta (8.8) | 0.90% | — | IBM Content Navigator | 24/3/2020 | 17/6/2026 | IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559. | |
| Modificada | Alta (8.8) | 1.4% | — | Atutor Acontent | 16/3/2020 | 17/6/2026 | An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions. | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Cloud Email SecurityCisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial… | |
| Modificada | Media (5.3) | 0.96% | — | IBM Content Navigator | 12/2/2020 | 17/6/2026 | IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815. | |
| Modificada | Media (5.3) | 1.6% | — | Dynamic Content Elements Project Dynamic Content Elements | 3/2/2020 | 17/6/2026 | The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request. | |
| Modificada | Media (4.3) | 0.82% | — | IBM Content Navigator | 28/1/2020 | 17/6/2026 | IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force ID: 171515. | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Accusoft Prizm Content Connect | 21/1/2020 | 16/6/2026 | Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability | |
| Modificada | Media (5.9) | 0.80% | — | Vmware Workspace ONE BoxerVmware Workspace ONE ContentVmware Workspace ONE Intelligent HUBVmware Workspace ONE Notebook+5 | 17/1/2020 | 17/6/2026 | VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. |