Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.69% | — | IBM Security Verify Access | 8/7/2022 | 17/6/2026 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081. | |
| Modificada | Media (6.5) | 0.97% | — | IBM Security Verify Access | 8/7/2022 | 17/6/2026 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079. | |
| Modificada | Media (5.4) | 0.46% | — | IBM Security Verify Access | 8/7/2022 | 17/6/2026 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (6.5) | 0.70% | — | IBM Security Verify Access | 31/3/2022 | 17/6/2026 | IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 2/2/2022 | 17/6/2026 | IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353. | |
| Modificada | Alta (7.5) | 0.97% | — | IBM Security Verify Access | 10/1/2022 | 17/6/2026 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040. | |
| Modificada | Media (5.3) | 0.91% | — | IBM Security Verify Access | 10/1/2022 | 17/6/2026 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038 | |
| Modificada | Alta (7.5) | 0.66% | — | IBM Security Verify Access | 10/1/2022 | 17/6/2026 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067. | |
| Modificada | Media (5.4) | 0.45% | — | IBM Security Verify Access | 10/1/2022 | 17/6/2026 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209563. | |
| Modificada | Baja (2.7) | 0.94% | — | IBM Security Verify Access | 10/1/2022 | 17/6/2026 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515. | |
| Modificada | Alta (8) | 0.37% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483. | |
| Modificada | Media (6.8) | 0.94% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600. | |
| Modificada | Media (6.5) | 0.68% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918 | |
| Modificada | Baja (3.5) | 0.55% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that… | |
| Modificada | Alta (7.2) | 1.8% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 198813 | |
| Modificada | Media (4.8) | 0.49% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198661. | |
| Modificada | Baja (2.7) | 0.97% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660 | |
| Modificada | Media (4.9) | 1.9% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300. | |
| Modificada | Media (4.4) | 0.48% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 198299 | |
| Modificada | Media (4.4) | 0.25% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. IBM X-Force ID: 197980. | |
| Modificada | Baja (2.7) | 0.97% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973 | |
| Modificada | Media (5.3) | 0.94% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972. | |
| Modificada | Alta (7.5) | 0.71% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969 | |
| Modificada | Media (4.9) | 0.65% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Security Access ManagerIBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user. |