Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | IBM Spectrum Protect | 28/8/2020 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613. | |
| Modificada | Alta (8.1) | 1.6% | — | IBM Spectrum VirtualizeIBM Flashsystem V5000 FirmwareIBM Flashsystem V7200 FirmwareIBM Flashsystem V9000 Firmware+7 | 17/8/2020 | 17/6/2026 | IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678. | |
| Modificada | Media (5.5) | 0.24% | — | IBM Spectrum Protect Plus | 4/8/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372. | |
| Modificada | Crítica (9.8) | 1.7% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials. | |
| Modificada | Crítica (9.8) | 1.7% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials. | |
| Modificada | Crítica (9.8) | 2.1% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted. | |
| Modificada | Crítica (9.4) | 1.4% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are… | |
| Modificada | Crítica (9.8) | 0.95% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented… | |
| Modificada | Baja (2.4) | 0.35% | — | Baxter Sigma Spectrum Infusion System Firmware | 29/6/2020 | 17/6/2026 | Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus including device settings, view calibration values, network… | |
| Modificada | Media (5.9) | 1.2% | — | IBM Spectrum Protect Plus | 26/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used between the application and server. IBM X-Force ID: 183935. | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation… | |
| Modificada | Media (6.5) | 0.94% | — | IBM Spectrum Protect Plus | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779. | |
| Modificada | Media (6.5) | 2.7% | — | IBM Spectrum Protect Plus | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726. | |
| Modificada | Alta (8) | 1.9% | — | IBM Spectrum Protect Plus | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725. | |
| Modificada | Crítica (9.8) | 13% | — | IBM Spectrum Protect Plus | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211.… | |
| Modificada | Media (5.4) | 0.82% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading… | |
| Modificada | Crítica (9.8) | 1.6% | — | IBM Spectrum Protect Plus | 15/6/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158. | |
| Modificada | Media (4.9) | 0.85% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178761. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423. | |
| Modificada | Media (6.5) | 0.76% | — | IBM Spectrum Scale | 27/5/2020 | 17/6/2026 | IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to missing function level access control. IBM X-Force ID: 178414 | |
| Modificada | Media (5.3) | 1.3% | — | IBM Spectrum Scale | 19/5/2020 | 17/6/2026 | The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability… |