Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.57%—Seeyon G6 Government Collaborative System30/3/202117/6/2026
Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' parameter to 'seeyon/hrSalary.do'.
ModificadaMedia (5.5)0.37%—IBM Security Identity Governance AND Intelligence9/2/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of authentication credentials. IBM X-Force ID: 192913.
ModificadaMedia (5.3)1.1%—IBM Security Identity Governance AND Intelligence9/2/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.
ModificadaAlta (8.2)1.7%—IBM Security Identity Governance AND Intelligence9/2/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.
ModificadaMedia (5.3)0.30%—IBM Security Identity Governance AND Intelligence9/2/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.
ModificadaMedia (6.5)0.60%—IBM Security Identity Governance AND Intelligence9/2/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, rendering the application unusuable. IBM X-Force ID: 189375.
ModificadaMedia (6.5)2.2%—CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+626/1/202125/8/2026
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
ModificadaMedia (5.9)0.67%—IBM Security Identity Governance AND Intelligence21/1/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
ModificadaMedia (6.5)0.32%—IBM Security Identity Governance AND Intelligence21/1/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192427.
ModificadaMedia (4.3)1.4%—IBM Security Identity Governance AND Intelligence21/1/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and…
ModificadaCrítica (9.8)1.7%—IBM Security Identity Governance AND Intelligence21/1/202117/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.
ModificadaAlta (7.5)10%💥 ExploitNewgensoft Egov30/12/202017/6/2026
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
ModificadaBaja (3.7)0.91%—IBM Security Identity Governance AND Intelligence5/8/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.
ModificadaBaja (2.7)0.98%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175484.
ModificadaMedia (6.5)0.91%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485.
ModificadaAlta (7.1)1.4%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 175481.
ModificadaAlta (7.5)1.2%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
ModificadaMedia (5.3)1.1%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumeration. IBM X-Force ID: 175422.
ModificadaMedia (5.3)0.77%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the…
ModificadaAlta (7.5)1.1%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
ModificadaMedia (6.5)0.81%—IBM Security Identity Governance AND Intelligence28/5/202017/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input validation. IBM X-Force ID: 175335.
ModificadaMedia (6.5)1.4%💥 PoCAlberta AbtracetogetherGOV Protego SafeHealth CovidsafeTracetogether14/5/202017/6/2026
The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether…
ModificadaMedia (4.3)0.63%—SAP Master Data Governance12/5/202017/6/2026
SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.
ModificadaAlta (8.8)0.98%—SAP Master Data Governance (s4core)SAP Master Data Governance (s4fnd)Master Data Governance (sap BS Fnd)12/5/202017/6/2026
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Orbitaley — Vulnerabilidades