Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.85%💥 ExploitWso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+524/10/202517/6/2026
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this…
AnalizadaMedia (4.8)0.62%💥 ExploitWso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+524/10/202517/6/2026
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrieved content was…
ModificadaMedia (5.5)0.15%—IBM Sterling B2B IntegratorIBM Sterling File Gateway16/10/202517/6/2026
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
AnalizadaMedia (5.7)0.21%—Wso2 Enterprise IntegratorWso2 Enterprise Service BUS16/10/202517/6/2026
An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to…
AnalizadaMedia (6.5)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+1116/10/202525/9/2026
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This…
AnalizadaAlta (7.2)0.54%—Wso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM26/9/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this…
AnalizadaMedia (6.5)0.32%—Wso2 API ManagerWso2 Micro Integrator23/9/202517/6/2026
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This…
AnalizadaMedia (4.8)0.19%—IBM Sterling B2B IntegratorIBM Sterling File Gateway4/9/202517/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the…
AnalizadaMedia (4.9)0.26%—IBM Sterling B2B IntegratorIBM Sterling File Gateway4/9/202517/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system.
AplazadaCrítica (9.1)0.37%—Extremeidea Bidorbuy Store IntegratorAI28/8/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Remote Code Inclusion.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0.
AnalizadaMedia (6.5)0.25%—IBM Sterling B2B IntegratorIBM Sterling File Gateway19/8/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
AnalizadaMedia (5.4)0.24%—IBM Sterling B2B IntegratorIBM Sterling File Gateway19/8/202517/6/2026
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaMedia (6.1)0.21%—IBM Sterling B2B IntegratorIBM Sterling File Gateway18/7/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
AnalizadaMedia (5.4)0.19%—IBM Sterling B2B IntegratorIBM Sterling File Gateway8/7/202517/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the…
AnalizadaMedia (5.4)0.19%—IBM Sterling B2B IntegratorIBM Sterling File Gateway8/7/202517/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…
AnalizadaMedia (4.3)0.21%—Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+223/6/202517/6/2026
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper…
AnalizadaMedia (4.8)0.21%—IBM Sterling B2B IntegratorIBM Sterling File Gateway18/6/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to…
AnalizadaMedia (4)0.14%—IBM Sterling B2B IntegratorIBM Sterling File Gateway18/6/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.
AnalizadaMedia (4.3)0.14%—IBM Sterling B2B IntegratorIBM Sterling File Gateway18/6/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AnalizadaMedia (5.4)0.20%—IBM Sterling B2B IntegratorIBM Sterling File Gateway18/6/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to…
AnalizadaMedia (5.2)0.53%—Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+22/6/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary…
AplazadaMedia (6.8)17%—Wso2 API ManagerAIWso2 Identity ServerAIWso2 Enterprise IntegratorAI2/6/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server. By leveraging this vulnerability, an attacker could upload…
AnalizadaMedia (4.3)0.20%—Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager2/6/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the…
AplazadaAlta (7.1)0.14%—Gagan Deep Singh Postmarkapp Email IntegratorAI31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gagan Deep Singh PostmarkApp Email Integrator postmarkapp-email-integrator allows Cross Site Request Forgery.This issue affects PostmarkApp Email Integrator: from n/a through <= 2.4.
AplazadaMedia (4.3)0.28%—Gagan Deep Singh Postmarkapp Email IntegratorAI31/3/202517/6/2026
Missing Authorization vulnerability in Gagan Deep Singh PostmarkApp Email Integrator postmarkapp-email-integrator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostmarkApp Email Integrator: from n/a through <= 2.4.
Orbitaley — Vulnerabilidades