Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+918/2/202016/6/2026
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
ModificadaAlta (7.8)0.72%—Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server16/2/202017/6/2026
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.
ModificadaAlta (8.8)0.99%—Dell RSA Identity Governance AND Lifecycle18/12/201917/6/2026
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access…
ModificadaCrítica (9.8)2.0%—Dell RSA Identity Governance AND Lifecycle18/12/201917/6/2026
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent…
ModificadaMedia (5.4)0.50%—Dell RSA Identity Governance AND Lifecycle18/12/201917/6/2026
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts.…
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaCrítica (9.8)2.1%—Govicture Pc530 Firmware1/10/201917/6/2026
Victure PC530 devices allow unauthenticated TELNET access as root.
ModificadaAlta (7.8)0.32%—Dell RSA Identity Governance AND LifecycleDell RSA VIA Lifecycle AND Governance11/9/201917/6/2026
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Office 365 connector debug log file. An authenticated malicious local user with…
ModificadaMedia (5.4)0.78%—Dell RSA Identity Governance AND LifecycleDell RSA VIA Lifecycle AND Governance11/9/201917/6/2026
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-site scripting vulnerability in the Access Request module. A remote authenticated malicious user could potentially exploit this vulnerability to store malicious HTML or JavaScript…
ModificadaAlta (8.8)1.2%—Dell RSA Identity Governance AND LifecycleDell RSA VIA Lifecycle AND Governance11/9/201917/6/2026
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain…
ModificadaAlta (8.1)3.2%💥 ExploitDell RSA Identity Governance AND LifecycleDell RSA VIA Lifecycle AND Governance11/9/201917/6/2026
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify…
ModificadaCrítica (9.8)1.4%—GOV Ccd-data-store-api26/8/201917/6/2026
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.
ModificadaMedia (5.4)0.67%—IBM Infosphere Information ServerIBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud1/7/201917/6/2026
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
ModificadaAlta (7.1)2.0%—IBM Infosphere Information ServerIBM Infosphere Governance CatalogIBM Infosphere Information Server ON CloudIBM Infosphere Information Server Business Glossary+117/6/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
ModificadaMedia (4.3)0.98%—IBM Infosphere Information AnalyzerIBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud6/6/201917/6/2026
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaMedia (4.3)0.54%—IBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud5/3/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.
ModificadaMedia (6.1)1.0%—IBM Infosphere Information Governance CatalogIBM Infosphere Information Server ON Cloud5/3/201917/6/2026
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to…
ModificadaMedia (4.3)0.98%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks against the system. IBM X-Force ID: 153430.
ModificadaMedia (4.3)0.98%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429.
ModificadaMedia (4.3)1.1%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will…
ModificadaMedia (6.1)0.89%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaAlta (7.5)0.73%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is…
ModificadaMedia (6.1)1.2%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…
ModificadaCrítica (9.8)0.84%—IBM Security Identity Governance AND Intelligence21/2/201917/6/2026
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153386.
Orbitaley — Vulnerabilidades