Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.28%—IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access25/7/202417/6/2026
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
ModificadaAlta (7.5)0.38%—IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access25/7/202417/6/2026
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.
ModificadaBaja (3.7)0.31%—IBM Sterling B2B Integrator17/7/202417/6/2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
ModificadaMedia (5.4)0.26%—IBM Sterling B2B Integrator27/6/202417/6/2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…
ModificadaMedia (5.4)0.22%—IBM Sterling B2B Integrator27/6/202417/6/2026
IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.
AnalizadaMedia (4.3)0.42%—Oracle WEB Applications Desktop Integrator16/4/202417/6/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop…
AnalizadaMedia (5.4)0.38%—IBM Sterling B2B Integrator12/4/202417/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaMedia (5.4)0.32%—IBM Sterling B2B Integrator12/4/202417/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaMedia (5.4)0.32%—IBM Sterling B2B Integrator12/4/202417/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
AnalizadaMedia (6.1)0.33%—Oracle WEB Applications Desktop Integrator17/2/202417/6/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications…
AnalizadaCrítica (9.8)0.59%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
AnalizadaCrítica (9.8)0.64%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
ModificadaMedia (4.3)0.27%—IBM Sterling B2B Integrator9/2/202417/6/2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…
ModificadaMedia (6.5)0.61%—IBM Sterling B2B Integrator9/2/202417/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827.
ModificadaCrítica (9.1)0.69%—Prestashow Google Integrator8/1/202417/6/2026
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
ModificadaMedia (4.8)0.41%—Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+518/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
ModificadaAlta (7.5)0.48%—Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Enterprise Integrator+315/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
ModificadaMedia (5.5)0.23%—IBM Sterling B2B Integrator22/11/202317/6/2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.
ModificadaAlta (8.8)0.29%—IBM Sterling B2B Integrator22/11/202317/6/2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824.
ModificadaAlta (7.8)0.20%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.22%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.20%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.
ModificadaMedia (5.5)0.21%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.21%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.7)0.12%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
Orbitaley — Vulnerabilidades