Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)1.8%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.1 allows remote authenticated users to bypass intended object-access restrictions via the datagraph.
ModificadaMedia (4)1.6%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 does not perform access-control checks for contained objects, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaBaja (3.5)1.4%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent header.
ModificadaMedia (4.3)1.8%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)1.4%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.6%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4)2.4%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)2.0%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by…
ModificadaBaja (3.5)1.6%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified…
ModificadaMedia (4)2.1%—Openstack Image Registry AND Delivery Service (glance)Canonical Ubuntu Linux25/8/201417/6/2026
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large…
ModificadaMedia (4.3)1.2%—IBM Websphere Service Registry AND Repository30/5/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6)2.0%—Openstack IcehouseOpenstack Image Registry AND Delivery Service (glance)27/4/201417/6/2026
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
ModificadaBaja (2.6)0.31%—Openstack Image Registry AND Delivery Service (glance)14/2/201417/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
ModificadaBaja (3.5)1.1%—IBM Websphere Service Registry AND Repository17/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.
ModificadaBaja (2.1)0.35%—Openstack Image Registry AND Delivery Service (glance)23/11/201316/6/2026
The API before 2.1 in OpenStack Image Registry and Delivery Service (Glance) makes it easier for local users to inject images into arbitrary tenants by adding the tenant as a member of the image.
ModificadaMedia (4)3.0%💥 PoCOpenstack Image Registry AND Delivery Service (glance)Canonical Ubuntu Linux24/2/201316/6/2026
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading…
ModificadaMedia (5.5)2.7%—Openstack EssexOpenstack FolsomOpenstack Image Registry AND Delivery Service (glance)11/11/201216/6/2026
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
ModificadaMedia (5.5)3.3%—Openstack EssexOpenstack FolsomOpenstack Image Registry AND Delivery Service (glance)11/11/201216/6/2026
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
ModificadaMedia (6.5)0.89%💥 ExploitRyan Walberg PHP Gift Registry20/4/201216/6/2026
SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.
ModificadaMedia (4.3)0.84%—IBM Websphere Service Registry AND Repository11/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
ModificadaMedia (5)1.2%—IBM Websphere Service Registry AND Repository22/12/201016/6/2026
IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.
ModificadaMedia (4.3)1.1%—IBM Websphere Service Registry AND Repository10/8/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value parameter to…
ModificadaAlta (8.5)1.5%—HP SOA Registry Foundation31/3/201016/6/2026
Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote authenticated users to gain privileges via unknown vectors.
ModificadaMedia (4.3)1.6%—HP SOA Registry Foundation31/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (5)2.0%—HP SOA Registry Foundation31/3/201016/6/2026
Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to obtain "unauthorized access to data" via unknown vectors.
Orbitaley — Vulnerabilidades