Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.78% | — | Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contains vulnerabilities where an authenticated user can change settings that can theoretically adversely impact other users. Affected… | |
| Modificada | Crítica (9.8) | 2.5% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver… | |
| Modificada | Alta (8.8) | 2.1% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric,… | |
| Modificada | Alta (8.8) | 0.95% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric… | |
| Modificada | Media (6.1) | 0.69% | — | Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain cross site scripting (XSS) and cross-site request forgery… | |
| Modificada | Alta (8.1) | 2.9% | — | Tibco Activematrix Businessworks | 9/4/2019 | 17/6/2026 | The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic… | |
| Modificada | Media (4.3) | 1.2% | — | Tibco Data Science FOR AWSTibco Spotfire Data Science | 26/3/2019 | 17/6/2026 | The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science… | |
| Modificada | Alta (8.1) | 1.7% | — | Tibco Data Science FOR AWSTibco Spotfire Data Science | 26/3/2019 | 17/6/2026 | The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and… | |
| Modificada | Media (5.4) | 1.1% | — | Tibco Data Science FOR AWSTibco Spotfire Data Science | 26/3/2019 | 17/6/2026 | The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users.… | |
| Modificada | Alta (7.7) | 1.0% | — | Tibco Jasperreports Server | 7/3/2019 | 17/6/2026 | The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Media (5.4) | 1.2% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting… | |
| Modificada | Crítica (9.8) | 3.1% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows… | |
| Analizada | Media (6.5) | 79% | ⚠ Explotación activa💥 Exploit | Tibco Jasperreports LibraryTibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO… | |
| Modificada | Alta (7.5) | 1.7% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability… | |
| Modificada | Media (6.1) | 1.1% | — | Tibco Silver Fabric | 13/2/2019 | 17/6/2026 | The SOAP Admin API component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that may allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions up to and including 5.8.1. | |
| Modificada | Crítica (9.8) | 3.1% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 16/1/2019 | 17/6/2026 | The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a target account, independent of… | |
| Modificada | Media (6.1) | 1.5% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 16/1/2019 | 17/6/2026 | The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform… | |
| Modificada | Media (5.3) | 1.2% | — | Tibco Spotfire Analytics Platform FOR AWSTibco Spotfire Server | 16/1/2019 | 17/6/2026 | The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to restrict users with read-only access from modifying files stored in the Spotfire Library, only when the Spotfire Library is… | |
| Modificada | Crítica (9.9) | 1.2% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 11/12/2018 | 17/6/2026 | The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to credentials to other systems. Affected releases are TIBCO Software… | |
| Modificada | Media (5.4) | 1.2% | — | Tibco Statistica Server | 26/11/2018 | 17/6/2026 | The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica Server versions up to and including 13.4.0. | |
| Modificada | Alta (8.8) | 0.58% | — | Tibco Datasynapse Gridserver Manager | 13/11/2018 | 17/6/2026 | The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Enterprise Message Service | 6/11/2018 | 17/6/2026 | The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF)… | |
| Modificada | Alta (8.8) | 0.67% | — | Tibco RendezvousTibco Rendezvous FOR Z/linuxTibco Rendezvous FOR Z/osTibco Rendezvous Network Server+1 | 6/11/2018 | 17/6/2026 | The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rendezvous Daemon Manager (rvdm) components of TIBCO Software Inc.'s TIBCO Rendezvous, TIBCO Rendezvous Developer Edition, TIBCO Rendezvous for z/Linux, TIBCO Rendezvous for… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Messaging - Apache Kafka Distribution - Schema Repository | 6/11/2018 | 17/6/2026 | The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform… | |
| Modificada | Alta (8.8) | 0.88% | — | Tibco FTL | 6/11/2018 | 17/6/2026 | The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO… |