Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.3% | — | III Encore Discovery Solution | 29/8/2014 | 17/6/2026 | Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.8) | 2.1% | — | III Encore Discovery Solution | 29/8/2014 | 17/6/2026 | Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 29/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote attackers to inject… | |
| Modificada | Baja (3.5) | 1.9% | — | IBM Tivoli Application Dependency Discovery Manager | 1/7/2014 | 16/6/2026 | Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Tivoli Application Dependency Discovery Manager | 29/1/2014 | 16/6/2026 | The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the… | |
| Modificada | Media (6.4) | 1.4% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 10/1/2014 | 17/6/2026 | IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows… | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 10/1/2014 | 17/6/2026 | SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote… | |
| Modificada | Alta (7.1) | 25% | 💥 PoC | IBM JavaOracle JDKOracle JREOracle Jrockit+11 | 23/7/2013 | 16/6/2026 | XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Tivoli Application Dependency Discovery Manager | 6/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Tivoli Application Dependency Discovery Manager | 6/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5.8) | 0.94% | — | IBM Tivoli Application Dependency Discovery Manager | 6/3/2013 | 16/6/2026 | The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack. | |
| Modificada | Media (5) | 2.5% | — | HP Discovery&dependency Mapping Inventory | 25/3/2011 | 16/6/2026 | HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community. | |
| Modificada | Media (4.3) | 1.7% | — | HP Discovery&dependency Mapping Inventory | 22/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9) | 3.4% | — | HP Discovery&dependency Mapping Inventory | 17/11/2009 | 16/6/2026 | Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4) | 1.8% | — | HP Discovery&dependency Mapping Inventory | 8/6/2009 | 16/6/2026 | Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors. | |
| Modificada | Alta (9) | 3.6% | — | HP Enterprise Discovery | 2/9/2008 | 16/6/2026 | Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it should be for HP Enterprise Discovery. | |
| Modificada | Alta (7.2) | 0.39% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 23/7/2007 | 16/6/2026 | Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges. | |
| Modificada | Alta (9.3) | 4.7% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of… | |
| Modificada | Alta (10) | 7.8% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 16/5/2007 | 16/6/2026 | Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet. | |
| Modificada | Media (5) | 1.5% | — | Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard | 21/1/2006 | 16/6/2026 | Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data". | |
| Modificada | Alta (7.5) | 1.4% | — | Symantec DiscoverySymantec ON Command Discovery | 27/10/2005 | 16/6/2026 | The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password. |