Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.7% | — | Dell Security Management Server | 6/3/2020 | 17/6/2026 | Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute… | |
| Modificada | Crítica (9.6) | 2.2% | — | Dell EMC Isilonsd Management Server | 17/4/2019 | 17/6/2026 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user. | |
| Modificada | Crítica (9.6) | 2.2% | — | Dell EMC Isilonsd Management Server | 17/4/2019 | 17/6/2026 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user. | |
| Modificada | Alta (7.5) | 1.8% | — | Symantec Encryption Management Server | 20/8/2018 | 17/6/2026 | The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or… | |
| Modificada | Media (5.4) | 0.72% | — | IBM Infosphere Master Data Management Server | 3/8/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.… | |
| Modificada | Media (5.7) | 1.2% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly… | |
| Modificada | Media (5.4) | 0.73% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited. | |
| Modificada | Alta (8.8) | 0.67% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Alta (8.8) | 0.56% | — | IBM Infosphere Master Data Management Server | 31/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Infosphere Master Data Management Server | 19/7/2017 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463. | |
| Modificada | Crítica (9.1) | 1.6% | — | Symantec Encryption Management Server | 18/2/2016 | 17/6/2026 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access. | |
| Modificada | Alta (7.8) | 0.28% | — | Symantec Encryption Management Server | 18/2/2016 | 17/6/2026 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file. | |
| Modificada | Alta (7.5) | 1.7% | — | Symantec Encryption Management Server | 18/2/2016 | 17/6/2026 | The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests. | |
| Modificada | Alta (7.5) | 1.6% | — | Symantec Encryption Management Server | 18/2/2016 | 17/6/2026 | The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Infosphere Master Data Management Server | 2/6/2015 | 17/6/2026 | Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Infosphere Master Data Management Server | 25/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.3% | — | IBM Infosphere Master Data Management Server | 25/5/2015 | 17/6/2026 | The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in… | |
| Modificada | Alta (9) | 8.1% | 💥 Exploit | Symantec Encryption Management ServerSymantec PGP Universal Server | 1/2/2015 | 17/6/2026 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action. | |
| Modificada | Media (5) | 1.1% | — | Symantec Encryption Management ServerSymantec PGP Universal Server | 1/2/2015 | 17/6/2026 | The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Media (4) | 0.80% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaborative Server | 22/12/2014 | 17/6/2026 | The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's… |