Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Tibco Managed File Transfer Platform Server | 9/6/2020 | 17/6/2026 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Crítica (9.8) | 1.4% | — | Tibco Managed File Transfer Platform Server | 9/6/2020 | 17/6/2026 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable… | |
| Modificada | Alta (8.8) | 5.4% | — | Tibco Jasperreports LibraryTibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an… | |
| Modificada | Crítica (9.8) | 3.5% | — | Tibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server… | |
| Modificada | Alta (8.8) | 1.3% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 11/3/2020 | 17/6/2026 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permissions to the Spotfire Library, but not "Script Author" group permission, to modify attributes of files… | |
| Modificada | Media (5.4) | 0.68% | — | Tibco EBX | 19/2/2020 | 17/6/2026 | The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7. | |
| Modificada | Media (5.4) | 0.61% | — | Tibco Patterns - Search | 28/1/2020 | 17/6/2026 | The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that theoretically allow authenticated users to perform persistent cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Patterns - Search: versions 5.4.0 and below. | |
| Modificada | Media (5.4) | 0.73% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 17/12/2019 | 17/6/2026 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire… | |
| Modificada | Media (6.5) | 0.88% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 17/12/2019 | 17/6/2026 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to information that can lead to obtaining credentials used to access Spotfire data sources. The attacker… | |
| Modificada | Media (6.5) | 0.80% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 17/12/2019 | 17/6/2026 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have… | |
| Modificada | Alta (8) | 0.96% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 17/12/2019 | 17/6/2026 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write… | |
| Modificada | Media (5.4) | 0.72% | — | Tibco EBX Add-ons | 12/11/2019 | 17/6/2026 | The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13,… | |
| Modificada | Media (5.4) | 0.61% | — | Tibco EBX Add-ons | 12/11/2019 | 17/6/2026 | The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, version… | |
| Modificada | Crítica (9.6) | 0.97% | — | Tibco EBX | 12/11/2019 | 17/6/2026 | The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Media (5.4) | 0.68% | — | Tibco Master Data Management | 9/10/2019 | 17/6/2026 | The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0. | |
| Modificada | Crítica (9.9) | 3.7% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics Platform FOR AWS | 18/9/2019 | 17/6/2026 | The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs… | |
| Modificada | Crítica (10) | 3.7% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics Platform FOR AWS | 18/9/2019 | 17/6/2026 | The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account… | |
| Modificada | Alta (8.8) | 1.4% | — | Tibco FTL | 20/8/2019 | 17/6/2026 | The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls. This issue affects TIBCO FTL Community Edition 6.0.0; 6.0.1; 6.1.0, TIBCO FTL… | |
| Modificada | Alta (8.8) | 0.65% | — | Tibco Loglogic Enterprise Virtual ApplianceTibco Loglogic LOG Management IntelligenceTibco Loglogic Lx825 FirmwareTibco Loglogic Lx4025 Firmware+18 | 13/8/2019 | 17/6/2026 | The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as cross-site request forgery (CSRF) attacks.… | |
| Modificada | Crítica (9.9) | 0.91% | — | Tibco API Exchange Gateway | 8/8/2019 | 17/6/2026 | The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint,… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Media (5.3) | 1.6% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 14/5/2019 | 17/6/2026 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow a malicious user to undermine the integrity of comments and bookmarks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire… | |
| Modificada | Media (6.1) | 1.3% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 14/5/2019 | 17/6/2026 | The web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS… | |
| Modificada | Alta (8.8) | 1.5% | — | Tibco Spotfire Statistics Services | 14/5/2019 | 17/6/2026 | The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database,… | |
| Modificada | Media (6.1) | 1.1% | — | Tibco Activematrix BPMTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL could trick a user into visiting a… |