Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.35% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Crítica (9.8) | 0.33% | — | IBM Security Verify Governance | 6/6/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Security Verify Governance | 9/4/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Baja (3.3) | 0.15% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 22/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.14% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 21/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user. | |
| Analizada | Alta (7.8) | 0.24% | — | IBM Security Verify Access | 20/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation. | |
| Analizada | Alta (8.8) | 1.1% | — | IBM Security Verify Directory | 6/2/2025 | 17/6/2026 | IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Analizada | Alta (7.8) | 0.23% | — | IBM Security Verify Access | 6/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges. | |
| Analizada | Media (5.3) | 0.43% | — | IBM Security Verify Access | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. | |
| Analizada | Alta (7.5) | 0.25% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | |
| Analizada | Media (6.1) | 0.31% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (6.5) | 0.21% | — | IBM Security Verify Access | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Media (5.3) | 0.37% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Security Verify Directory | 31/1/2025 | 17/6/2026 | IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation. | |
| Analizada | Media (4.9) | 0.24% | — | IBM Security Verify Governance | 29/1/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input. | |
| Analizada | Media (5.9) | 0.24% | — | IBM Security Verify Governance | 29/1/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques. | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Alta (7.5) | 0.32% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system. | |
| Analizada | Media (6) | 0.14% | — | IBM Security Verify Bridge | 23/1/2025 | 17/6/2026 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service. | |
| Analizada | Crítica (9.8) | 0.27% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 20/1/2025 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify Access Docker | 19/12/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. | |
| Analizada | Crítica (9.8) | 0.32% | — | IBM Security Verify Access | 29/11/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. |