Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.28% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Alta (7.5) | 0.38% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | |
| Modificada | Baja (3.7) | 0.31% | — | IBM Sterling B2B Integrator | 17/7/2024 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Sterling B2B Integrator | 27/6/2024 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.… | |
| Modificada | Media (5.4) | 0.22% | — | IBM Sterling B2B Integrator | 27/6/2024 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508. | |
| Analizada | Media (4.3) | 0.42% | — | Oracle WEB Applications Desktop Integrator | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop… | |
| Analizada | Media (5.4) | 0.38% | — | IBM Sterling B2B Integrator | 12/4/2024 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (5.4) | 0.32% | — | IBM Sterling B2B Integrator | 12/4/2024 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (5.4) | 0.32% | — | IBM Sterling B2B Integrator | 12/4/2024 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Analizada | Media (6.1) | 0.33% | — | Oracle WEB Applications Desktop Integrator | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Analizada | Crítica (9.8) | 0.59% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Modificada | Media (4.3) | 0.27% | — | IBM Sterling B2B Integrator | 9/2/2024 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The… | |
| Modificada | Media (6.5) | 0.61% | — | IBM Sterling B2B Integrator | 9/2/2024 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827. | |
| Modificada | Crítica (9.1) | 0.69% | — | Prestashow Google Integrator | 8/1/2024 | 17/6/2026 | Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies. | |
| Modificada | Media (4.8) | 0.41% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+5 | 18/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console. | |
| Modificada | Alta (7.5) | 0.48% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Enterprise Integrator+3 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information. | |
| Modificada | Media (5.5) | 0.23% | — | IBM Sterling B2B Integrator | 22/11/2023 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034. | |
| Modificada | Alta (8.8) | 0.29% | — | IBM Sterling B2B Integrator | 22/11/2023 | 17/6/2026 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.7) | 0.12% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. |