Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.70% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 13/12/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130915. | |
| Modificada | Media (4.3) | 0.74% | — | IBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+3 | 11/12/2017 | 17/6/2026 | IBM Jazz Foundation Products could disclose sensitive information during a scan that could lead to further attacks against the system. IBM X-Force ID: 129619. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134064. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134063. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134000. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133260. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132927. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132494. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+3 | 27/11/2017 | 17/6/2026 | IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 131852. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131759. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Doors Next Generation | 27/11/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460. | |
| Modificada | Media (4.3) | 0.74% | — | IBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+3 | 27/11/2017 | 17/6/2026 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. IBM X-Force ID: 124631. | |
| Modificada | Media (4.3) | 0.92% | — | IBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+3 | 27/11/2017 | 17/6/2026 | IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359. | |
| Modificada | Media (4.3) | 0.74% | — | IBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+3 | 27/11/2017 | 17/6/2026 | IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868. | |
| Modificada | Alta (7.8) | 77% | 💥 Exploit | Cisco Unified Computing System Manager FirmwareCisco Firepower 9300 Security Appliance FirmwareCisco Firepower 4100 Next-generation Firewall Firmware | 2/11/2017 | 17/6/2026 | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to… | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 18/8/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126246. | |
| Modificada | Media (4.3) | 0.69% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 5/7/2017 | 17/6/2026 | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. | |
| Modificada | Media (4.3) | 3.4% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 13/6/2017 | 17/6/2026 | IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 13/6/2017 | 17/6/2026 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209. | |
| Modificada | Media (5.4) | 0.87% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next Generation | 7/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459. | |
| Modificada | Media (4.3) | 0.68% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 15/5/2017 | 17/6/2026 | IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781, | |
| Modificada | Alta (8.1) | 1.5% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Software Architect Design Manager+3 | 31/3/2017 | 17/6/2026 | IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784. |