Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+3 | 12/9/2014 | 17/6/2026 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to… | |
| Modificada | Media (6) | 0.78% | — | IBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Software Architect Design Manager | 10/9/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x… | |
| Modificada | Media (6) | 1.9% | — | IBM Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 30/7/2014 | 17/6/2026 | Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive. | |
| Modificada | Media (6) | 1.9% | — | IBM Rational Software Architect Design Manager | 30/7/2014 | 17/6/2026 | Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site. | |
| Modificada | Media (5.5) | 0.97% | — | IBM Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 21/4/2014 | 16/6/2026 | Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking. | |
| Modificada | Baja (2.1) | 0.61% | — | IBM Rational Software Architect Design ManagerIBM Rhapsody Design Manager | 14/12/2013 | 16/6/2026 | Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files. | |
| Modificada | Baja (2.1) | 0.61% | — | IBM Rational Software Architect Design ManagerIBM Rhapsody Design Manager | 14/12/2013 | 16/6/2026 | Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Rational Application Developer FOR WebsphereIBM Rational Software Architect | 23/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control… |