Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

281 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.28%—IBM Spectrum Control20/12/202217/6/2026
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.
ModificadaMedia (6.8)0.95%—IBM Spectrum Scale19/12/202217/6/2026
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.
ModificadaMedia (5.9)0.40%—IBM Spectrum Protect Plus14/12/202217/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.
ModificadaAlta (7.8)0.29%—IBM Spectrum Scale Container Native Storage Access6/12/202217/6/2026
IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
ModificadaAlta (7.5)1.8%—IBM Spectrum Protect Plus19/9/202217/6/2026
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID:…
ModificadaMedia (5.9)0.61%—IBM Spectrum Protect Plus19/9/202217/6/2026
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for…
ModificadaMedia (5.4)0.35%—Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware9/9/202217/6/2026
The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.
ModificadaAlta (8.1)0.67%—Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware9/9/202217/6/2026
The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.
ModificadaMedia (6.5)0.66%—Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware9/9/202217/6/2026
The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.
ModificadaMedia (4.2)0.47%—Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware9/9/202217/6/2026
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.5)0.61%—IBM Spectrum Scale Data Access Services10/8/202217/6/2026
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.
ModificadaAlta (7.5)2.6%💥 ExploitDW Spectrum Server Firmware19/7/202217/6/2026
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
ModificadaMedia (6.5)0.39%—IBM Spectrum Protect Server30/6/202217/6/2026
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center30/6/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
ModificadaCrítica (9.8)1.5%—IBM Spectrum Protect Server30/6/202217/6/2026
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative…
ModificadaMedia (5.5)0.16%—IBM Spectrum Protect Client30/6/202217/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
ModificadaAlta (7.5)1.1%—IBM Spectrum Protect Client30/6/202217/6/2026
IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.
ModificadaAlta (8.8)0.89%—IBM Spectrum Protect Plus Container Backup AND Restore30/6/202217/6/2026
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By…
ModificadaCrítica (9.8)1.1%—IBM Spectrum Protect Operations Center17/6/202217/6/2026
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain…
ModificadaAlta (8.8)0.40%—Siemens Spectrum Power 4Siemens Spectrum Power 7Siemens Spectrum Power Microgrid Management System14/6/202217/6/2026
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with…
ModificadaMedia (5.3)1.2%—IBM Spectrum Copy Data Management10/6/202217/6/2026
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219.
ModificadaMedia (5.4)0.65%—IBM Spectrum Copy Data Management10/6/202217/6/2026
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in…
ModificadaMedia (4.5)0.57%—IBM Spectrum Copy Data Management10/6/202217/6/2026
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that…
ModificadaAlta (8.8)0.34%—IBM Spectrum Copy Data Management10/6/202217/6/2026
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.
Orbitaley — Vulnerabilidades