Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.4% | — | IBM Lotus Connections | 15/6/2010 | 16/6/2026 | The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Lotus Connections | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the… | |
| Modificada | Alta (10) | 5.8% | — | IBM Lotus Notes | 29/4/2010 | 16/6/2026 | Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the… | |
| Modificada | Baja (2.1) | 0.35% | — | IBM Lotus Notes | 20/4/2010 | 16/6/2026 | IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG. | |
| Modificada | Alta (10) | 3.7% | — | IBM Lotus NotesSymantec Brightmail GatewaySymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+2 | 5/3/2010 | 16/6/2026 | Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a… | |
| Modificada | Media (4.3) | 1.0% | — | IBM Lotus Domino | 5/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920. | |
| Modificada | Media (6.8) | 0.57% | — | IBM Lotus Inotes | 3/3/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes." | |
| Modificada | Media (4.3) | 1.0% | — | IBM Lotus Inotes | 3/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes." | |
| Modificada | Alta (7.6) | 5.7% | — | IBM Domino WEB AccessIBM Lotus Inotes | 3/3/2010 | 16/6/2026 | Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ. | |
| Modificada | Alta (10) | 2.1% | — | IBM Lotus Inotes | 3/3/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.3% | — | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1,… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0,… | |
| Modificada | Media (4.3) | 2.1% | — | IBM Lotus Domino Server | 25/1/2010 | 16/6/2026 | The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. | |
| Modificada | Alta (10) | 2.4% | — | IBM Lotus Domino | 20/1/2010 | 16/6/2026 | Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Lotus WEB Content Management | 20/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Alta (10) | 1.5% | — | IBM Domino WEB AccessIBM Lotus InotesIBM Lotus Domino | 9/1/2010 | 16/6/2026 | IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU. | |
| Modificada | Alta (10) | 1.5% | — | IBM Lotus Inotes | 9/1/2010 | 16/6/2026 | Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58. | |
| Modificada | Alta (10) | 1.5% | — | IBM Lotus Inotes | 9/1/2010 | 16/6/2026 | Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5. | |
| Modificada | Alta (10) | 1.5% | — | IBM Lotus Inotes | 9/1/2010 | 16/6/2026 | Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH. | |
| Modificada | Alta (9.3) | 3.9% | — | RIM Blackberry Desktop SoftwareIBM Lotus Notes Intellisync | 4/11/2009 | 16/6/2026 | Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 1.0% | — | IBM Lotus Connections | 28/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | IBM Lotus Connections | 29/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Lotus Quickr | 29/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template. | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Lotus Notes | 9/9/2009 | 16/6/2026 | The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K. | |
| Modificada | Media (5) | 1.1% | — | IBM Lotus Domino | 8/9/2009 | 16/6/2026 | Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable… |