Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.11% | — | IBM Concert | 20/11/2025 | 17/6/2026 | IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output. | |
| Analizada | Media (5.5) | 0.11% | — | IBM Concert | 20/11/2025 | 17/6/2026 | IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying. | |
| Analizada | Media (6.1) | 0.20% | — | IBM Concert | 20/11/2025 | 17/6/2026 | IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.9) | 0.21% | — | IBM Concert | 20/11/2025 | 17/6/2026 | IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Concert | 28/10/2025 | 25/9/2026 | IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (5.5) | 0.13% | — | IBM Concert | 28/10/2025 | 25/9/2026 | IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release. | |
| Analizada | Media (5.3) | 0.24% | — | IBM Concert | 28/10/2025 | 25/9/2026 | IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input. | |
| Analizada | Alta (7.5) | 0.36% | — | IBM Concert | 8/9/2025 | 30/9/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | |
| Analizada | Alta (7.5) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (5.9) | 0.19% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | |
| Analizada | Media (5.9) | 0.21% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.1) | 0.21% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.18% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption. | |
| Analizada | Crítica (9.8) | 0.21% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | |
| Analizada | Alta (7.5) | 0.24% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering. | |
| Analizada | Alta (8.6) | 0.61% | — | Versa-networks Concerto | 21/5/2025 | 25/8/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on… | |
| Analizada | Crítica (10) | 45% | 💥 Exploit | Versa-networks Concerto | 21/5/2025 | 25/8/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race… | |
| Analizada | Crítica (9.2) | 82% | ⚠ Explotación activa💥 Exploit | Versa-networks Concerto | 21/5/2025 | 17/6/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto… | |
| Analizada | Media (5.3) | 0.51% | — | IBM Concert | 2/5/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Media (5.9) | 0.21% | — | IBM Concert | 2/5/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (6.5) | 0.25% | — | IBM Concert | 2/5/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |