Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain… | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 0.69% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL… | |
| Modificada | Baja (3.5) | 0.65% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management | 1/8/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via… | |
| Modificada | Media (6.3) | 1.1% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or… | |
| Modificada | Baja (2.1) | 0.37% | — | Novell Suse Lifecycle Management Server | 16/4/2014 | 16/6/2026 | SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.8) | 0.57% | — | IBM Infosphere Master Data Management Server | 16/3/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow… | |
| Modificada | Media (4) | 0.75% | — | Symantec Encryption Management Server | 7/2/2014 | 17/6/2026 | The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL. | |
| Modificada | Media (6.8) | 0.57% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 4/2/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4) | 0.85% | — | Checkpoint Management ServerCheckpoint Security Gateway | 26/1/2014 | 17/6/2026 | Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions. | |
| Modificada | Alta (7.2) | 0.48% | — | Novell Suse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast | 23/12/2013 | 16/6/2026 | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file. | |
| Modificada | Media (4.9) | 0.50% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/12/2013 | 16/6/2026 | Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. | |
| Modificada | Media (4.6) | 0.34% | — | Novell Suse Lifecycle Management Server | 10/12/2013 | 17/6/2026 | SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Novell Suse Lifecycle Management Server | 10/12/2013 | 16/6/2026 | SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaboration Server | 27/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script… | |
| Modificada | Alta (7.5) | 68% | 💥 Exploit | F5 NginxSuse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast+1 | 23/11/2013 | 16/6/2026 | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. | |
| Modificada | Media (4.3) | 0.89% | — | Symantec Encryption Management ServerSymantec PGP Universal Server | 31/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 21/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Media (6) | 0.93% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 21/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing… | |
| Modificada | Media (4.3) | 16% | — | Microsoft System Center Configuration ManagerMicrosoft Systems Management Server | 11/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability." | |
| Modificada | Media (4) | 38% | 💥 Exploit | Microsoft Forms ServerMicrosoft GrooveMicrosoft Groove Data Bridge ServerMicrosoft Groove Management Server+6 | 15/9/2011 | 16/6/2026 | Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint… |