Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.95% | — | IBM Websphere Portal | 13/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging incorrect IBM Connections integration. | |
| Modificada | Media (5) | 1.2% | — | IBM Websphere Portal | 21/8/2013 | 16/6/2026 | IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Websphere Portal | 16/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme. | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Websphere Portal | 3/6/2013 | 16/6/2026 | CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP… | |
| Modificada | Media (4.3) | 1.8% | — | IBM Websphere Portal | 3/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 3.1% | — | IBM Websphere Portal | 30/11/2012 | 16/6/2026 | Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI. | |
| Modificada | Media (5) | 2.8% | — | IBM Websphere Portal | 3/7/2012 | 16/6/2026 | Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Media (4.3) | 0.84% | — | IBM WEB Content ManagerIBM Websphere Portal | 17/7/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Portal | 26/5/2011 | 16/6/2026 | The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere Portal | 26/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 3.8% | — | IBM Websphere Portal | 28/1/2011 | 16/6/2026 | IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message." | |
| Modificada | Media (4.3) | 0.84% | — | IBM Websphere Portal | 9/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Websphere Portal | 12/4/2010 | 16/6/2026 | Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors. | |
| Modificada | Media (6.8) | 1.3% | — | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1,… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0,… | |
| Modificada | Media (4.3) | 0.84% | — | IBM Websphere Portal | 25/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Websphere Portal | 2/12/2009 | 16/6/2026 | Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Websphere Portal | 2/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag. | |
| Modificada | Media (4.3) | 1.6% | — | IBM Integrated Solutions ConsoleIBM Websphere Application ServerIBM Websphere Portal | 3/6/2009 | 16/6/2026 | IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM)… | |
| Modificada | Media (4.4) | 0.42% | — | IBM Websphere PortalOracle Application Server | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008. | |
| Modificada | Media (4.4) | 0.42% | — | Oracle Application ServerIBM Websphere Portal | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML. | |
| Modificada | Media (4.4) | 0.42% | — | IBM Websphere PortalOracle Application Server | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010. | |
| Modificada | Alta (10) | 1.5% | — | IBM Websphere Portal | 19/12/2008 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI." | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Websphere Portal | 4/8/2008 | 16/6/2026 | IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors. | |
| Modificada | Media (6.4) | 1.2% | — | IBM Websphere Portal | 19/6/2007 | 16/6/2026 | SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter. |