Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.4% | — | IBM Spss Modeler | 1/1/2013 | 16/6/2026 | IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference. | |
| Modificada | Media (6.4) | 1.4% | — | Fujitsu Interstage Application Server EnterpriseFujitsu Interstage Application Server PlusFujitsu Interstage Application Server Standard JFujitsu Interstage Application Server Plus Developer+4 | 12/6/2008 | 16/6/2026 | Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | Fujitsu Interstage Application Server EnterpriseFujitsu Interstage Application Server PlusFujitsu Interstage Application Server Standard JFujitsu Interstage Apworks Enterprise+4 | 8/3/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Fujitsu Interstage Smart Repository, as used in multiple Fujitsu Interstage products, allow remote attackers to cause a denial of service (daemon crash) via (1) an invalid request or (2) a large amount of data sent to the registered attribute value. | |
| Modificada | Media (6) | 1.2% | — | IBM Websphere Business Modeler | 23/1/2008 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's… | |
| Modificada | Media (4.3) | 1.5% | — | Broadcom Erwin Process Modeler | 13/10/2007 | 16/6/2026 | Unspecified vulnerability in CA ERwin Process Modeler (formerly AllFusion Process Modeler) 7.2 might allow user-assisted remote attackers to cause a denial of service via a crafted Data Standards File (Datatype Standards File). | |
| Modificada | Alta (10) | 3.5% | — | Broadcom Erwin Process Modeler | 11/7/2007 | 16/6/2026 | Buffer overflow in LICRCMD.EXE in CA ERwin Process Modeler (formerly AllFusion Process Modeler) 7.1 allows attackers to execute arbitrary code via a long filename. NOTE: the researcher does not suggest any circumstances in which the filename would come from an untrusted source, and therefore perhaps the issue does not… |