Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.47% | — | IBM Lotus Domino | 27/3/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Lotus Domino | 27/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.5) | 1.9% | — | IBM Lotus Domino | 27/3/2013 | 16/6/2026 | The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Lotus Domino | 27/3/2013 | 16/6/2026 | Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY. | |
| Modificada | Baja (1.5) | 0.28% | — | IBM Lotus Inotes | 26/3/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Lotus Inotes | 26/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Lotus Domino | 27/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 1.0% | — | IBM Lotus Domino | 27/2/2013 | 16/6/2026 | Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Alta (9.3) | 6.9% | — | IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+12 | 11/1/2013 | 16/6/2026 | Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control… | |
| Modificada | Alta (9.3) | 6.9% | — | IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+12 | 11/1/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli… | |
| Modificada | Alta (9.3) | 6.9% | — | IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+12 | 11/1/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli… | |
| Modificada | Alta (9.3) | 5.1% | — | IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+12 | 11/1/2013 | 16/6/2026 | Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Lotus Foundations Start | 19/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (2) Last Name field. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Lotus Notes | 19/12/2012 | 16/6/2026 | IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68. | |
| Modificada | Media (6.8) | 1.3% | — | IBM Lotus Notes Traveler | 8/10/2012 | 16/6/2026 | servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (6.8) | 0.61% | — | IBM Lotus Notes Traveler | 8/10/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers to hijack the authentication of arbitrary users for requests that create problem reports via a getReportProblem upload action. | |
| Modificada | Baja (2.6) | 0.88% | — | IBM Lotus Notes Traveler | 8/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via the redirectURL parameter, a different vulnerability than CVE-2012-4824 and CVE-2012-4825. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Lotus Notes Traveler | 8/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before 8.5.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) userId or (2) address parameter in a getClientConfigFile action. | |
| Modificada | Media (5.8) | 1.1% | — | IBM Lotus Notes Traveler | 8/10/2012 | 16/6/2026 | Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirectURL parameter. | |
| Modificada | Media (6.9) | 0.42% | — | IBM Lotus Notes | 7/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the current working directory, as demonstrated by a directory that contains a .vcf, .vcs, or .ics file. NOTE: the provenance of this information is… | |
| Modificada | Media (6.9) | 0.35% | — | IBM Lotus Symphony | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Domino | 21/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Lotus Domino | 21/8/2012 | 16/6/2026 | Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers. | |
| Modificada | Baja (3.5) | 3.0% | 💥 Exploit | IBM Lotus Protector FOR Mail SecurityIBM Proventia Network Mail Security System Firmware | 27/7/2012 | 16/6/2026 | Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | IBM Proventia Network Mail Security System FirmwareIBM Proventia Network Mail Security SystemIBM Lotus Protector FOR Mail Security | 20/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string. |