Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.13%—IBM Security Verify Governance22/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
ModificadaMedia (6.1)0.31%—IBM Security Verify Governance22/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225004.
ModificadaMedia (5.3)0.38%—IBM Security Verify Governance22/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.
ModificadaAlta (7.5)0.41%—IBM Security Verify Governance22/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
ModificadaAlta (8.8)0.91%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
ModificadaMedia (6.7)0.94%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
ModificadaMedia (5.3)0.71%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
ModificadaCrítica (9.8)0.50%—IBM Security Verify Governance17/8/202217/6/2026
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
ModificadaCrítica (9.8)0.85%—Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+5616/8/202217/6/2026
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of…
ModificadaAlta (7.5)0.74%—IBM Security Verify Governance14/7/202217/6/2026
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.
ModificadaAlta (7.5)0.40%—IBM Security Verify Governance14/7/202217/6/2026
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
ModificadaAlta (7.5)0.99%—IBM Security Verify Governance14/7/202217/6/2026
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
ModificadaBaja (3.8)0.60%—IBM Security Verify Governance14/7/202217/6/2026
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
ModificadaMedia (6.5)1.2%—Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server20/5/202217/6/2026
In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client…
ModificadaMedia (5.3)0.91%—IBM Security Identity Governance AND Intelligence17/5/202217/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks against the system. IBM X-Force ID: 192208.
ModificadaMedia (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaAlta (7.8)0.39%—Govicture Wr1200 Firmware30/11/202117/6/2026
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).
ModificadaAlta (8.8)4.6%—Govicture Wr1200 Firmware30/11/202117/6/2026
An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute…
ModificadaMedia (6.5)0.63%—Govicture Wr1200 Firmware30/11/202117/6/2026
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker…
ModificadaCrítica (9.8)1.4%—Govicture Pc420 Firmware30/8/202117/6/2026
Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions.
ModificadaMedia (5.4)1.3%—CkeditorDebian LinuxFedoraproject FedoraOracle Application Express+813/8/202117/6/2026
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It…
ModificadaMedia (5.4)1.2%—CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+912/8/202117/6/2026
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaBaja (3.7)0.66%—GOV Imposto DE Renda DA Pessoa Fisica 202112/6/202117/6/2026
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
ModificadaMedia (4.8)9.9%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+5613/4/202125/8/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
Orbitaley — Vulnerabilidades