Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.24% | — | IBM Concert | 28/10/2025 | 25/9/2026 | IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input. | |
| Analizada | Alta (7.5) | 0.36% | — | IBM Concert | 8/9/2025 | 30/9/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | |
| Analizada | Alta (7.5) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (5.9) | 0.19% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | |
| Analizada | Media (5.9) | 0.21% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.1) | 0.21% | — | IBM Concert | 1/9/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.18% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption. | |
| Analizada | Crítica (9.8) | 0.21% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | |
| Analizada | Alta (7.5) | 0.24% | — | IBM Concert | 18/8/2025 | 17/6/2026 | IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering. | |
| Aplazada | Alta (7.2) | 0.22% | — | Teconceptheme AllmartAI | 4/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (5.9) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.1) | 0.86% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.1% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (6.9) | 0.62% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (8.6) | 0.61% | — | Versa-networks Concerto | 21/5/2025 | 25/8/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on… | |
| Analizada | Crítica (10) | 45% | 💥 Exploit | Versa-networks Concerto | 21/5/2025 | 25/8/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race… | |
| Analizada | Crítica (9.2) | 82% | ⚠ Explotación activa💥 Exploit | Versa-networks Concerto | 21/5/2025 | 17/6/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto… |