Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%—III Encore Discovery Solution29/8/201417/6/2026
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (5.8)2.1%—III Encore Discovery Solution29/8/201417/6/2026
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
ModificadaMedia (4.3)1.2%—IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management29/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote attackers to inject…
ModificadaBaja (3.5)1.9%—IBM Tivoli Application Dependency Discovery Manager1/7/201416/6/2026
Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.
ModificadaAlta (7.5)1.1%—IBM Tivoli Application Dependency Discovery Manager29/1/201416/6/2026
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the…
ModificadaMedia (6.4)1.4%—IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management10/1/201417/6/2026
IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows…
ModificadaAlta (7.5)1.2%—IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management10/1/201417/6/2026
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote…
ModificadaAlta (7.1)25%💥 PoCIBM JavaOracle JDKOracle JREOracle Jrockit+1123/7/201316/6/2026
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8…
ModificadaBaja (3.5)0.94%—IBM Tivoli Application Dependency Discovery Manager6/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
ModificadaBaja (3.5)0.94%—IBM Tivoli Application Dependency Discovery Manager6/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (5.8)0.94%—IBM Tivoli Application Dependency Discovery Manager6/3/201316/6/2026
The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack.
ModificadaMedia (5)2.5%—HP Discovery&dependency Mapping Inventory25/3/201116/6/2026
HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.
ModificadaMedia (4.3)1.7%—HP Discovery&dependency Mapping Inventory22/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9)3.4%—HP Discovery&dependency Mapping Inventory17/11/200916/6/2026
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaMedia (4)1.8%—HP Discovery&dependency Mapping Inventory8/6/200916/6/2026
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.
ModificadaAlta (9)3.6%—HP Enterprise Discovery2/9/200816/6/2026
Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it should be for HP Enterprise Discovery.
ModificadaAlta (7.2)0.39%—Centennial DiscoveryNumara Asset ManagerSymantec Discovery23/7/200716/6/2026
Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges.
ModificadaAlta (9.3)4.7%—Centennial DiscoveryNumara Asset ManagerSymantec Discovery6/6/200716/6/2026
Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of…
ModificadaAlta (10)7.8%—Centennial DiscoveryNumara Asset ManagerSymantec Discovery16/5/200716/6/2026
Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet.
ModificadaMedia (5)1.5%—Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard21/1/200616/6/2026
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
ModificadaAlta (7.5)1.4%—Symantec DiscoverySymantec ON Command Discovery27/10/200516/6/2026
The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.