Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Broadcom CA Service Catalog5/1/202117/6/2026
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.
ModificadaAlta (7.5)1.4%—Wc-marketplace WC Catalog Enquiry27/8/201917/6/2026
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
ModificadaMedia (5.4)0.67%—IBM Infosphere Information ServerIBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud1/7/201917/6/2026
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
ModificadaMedia (4.8)0.88%—Cisco Prime Service Catalog20/6/201917/6/2026
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based…
ModificadaAlta (8.8)0.80%—Cisco Prime Service Catalog20/6/201917/6/2026
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection mechanisms on the web-based management…
ModificadaAlta (7.1)2.0%—IBM Infosphere Information ServerIBM Infosphere Governance CatalogIBM Infosphere Information Server ON CloudIBM Infosphere Information Server Business Glossary+117/6/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
ModificadaMedia (4.3)0.98%—IBM Infosphere Information AnalyzerIBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud6/6/201917/6/2026
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.
ModificadaMedia (5.5)0.21%—IBM Infosphere Information Server ON CloudIBM Watson Knowledge Catalog6/6/201917/6/2026
IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.
ModificadaMedia (4.3)0.54%—IBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud5/3/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.
ModificadaMedia (6.1)1.0%—IBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud5/3/201917/6/2026
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to…
ModificadaMedia (5.4)0.66%—IBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud15/2/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.
ModificadaMedia (5.4)0.92%—Cisco Prime Service Catalog8/11/201817/6/2026
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is…
ModificadaAlta (8.6)1.6%—SAP Supplier Relationship Management MDM Catalog14/8/201817/6/2026
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
ModificadaMedia (5.3)1.4%—SAP Supplier Relationship Management MDM Catalog14/8/201817/6/2026
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
ModificadaMedia (6.5)0.97%—Mcafee Common Catalog7/6/201817/6/2026
External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential information via a crafted HTTP request parameter.
ModificadaMedia (6.5)2.7%—Cisco Prime Service Catalog2/5/201817/6/2026
A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to exhaustion of disk space. An attacker could exploit this vulnerability by performing certain operations that lead to excessive logging. A…
ModificadaMedia (6.1)1.2%—Cisco Prime Service Catalog22/2/201817/6/2026
A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface of an affected product. The vulnerability is due to insufficient validation of user-supplied input…
ModificadaAlta (8.8)0.83%—Cisco Prime Service Catalog18/1/201817/6/2026
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of…
ModificadaMedia (6.5)1.3%—Cisco Prime Service Catalog30/11/201717/6/2026
A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit…
ModificadaMedia (6.1)0.92%—Etoilewebdesign Ultimate Product Catalog2/8/201717/6/2026
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.
ModificadaCrítica (9.8)1.8%—Etoilewebdesign Ultimate Product Catalog2/8/201717/6/2026
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item,…
ModificadaMedia (6.1)1.2%—Cisco Prime Service Catalog17/3/201717/6/2026
A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891.…
ModificadaMedia (5.4)1.1%—Cisco Prime Service Catalog3/2/201717/6/2026
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: 10.0_R2_tanggula.
ModificadaAlta (7.2)2.1%—Huge-it Catalog27/10/201617/6/2026
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
ModificadaAlta (7.2)2.3%—Huge-it Catalog21/10/201617/6/2026
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
Orbitaley — Vulnerabilidades