Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.16% | — | Coderscom WP Odoo Form IntegratorAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator wp-odoo-form-integrator allows Stored XSS.This issue affects WP Odoo Form Integrator: from n/a through <= 1.1.0. | |
| Analizada | Media (4.8) | 0.29% | — | IBM Sterling B2B Integrator | 11/3/2025 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Baja (2.7) | 0.29% | — | IBM Sterling B2B Integrator | 10/3/2025 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user. | |
| Analizada | Media (5.4) | 0.15% | — | Wso2 Enterprise Integrator | 27/2/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Media (4.3) | 0.29% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Sterling B2B Integrator | 31/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Media (5.3) | 0.27% | — | IBM Sterling B2B Integrator | 28/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques. | |
| Analizada | Crítica (9.8) | 0.35% | — | IBM Sterling B2B Integrator | 28/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Alta (7.5) | 0.32% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 23/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 23/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (8.8) | 0.97% | 💥 PoC | IBM Sterling B2B Integrator | 22/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data. | |
| Analizada | Media (6.4) | 0.24% | — | IBM Sterling B2B Integrator | 6/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 6/1/2025 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Analizada | Alta (8.8) | 0.67% | — | IBM Security Directory Integrator | 20/12/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Analizada | Media (5.4) | 0.26% | — | IBM Sterling B2B Integrator | 19/12/2024 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Crítica (9.8) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 16/8/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user. IBM X-Force ID: 228570. | |
| Analizada | Alta (8.5) | 0.16% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/8/2024 | 17/6/2026 | Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 30/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID:… |