Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | IBM Websphere Application Server | 30/7/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300. | |
| Modificada | Alta (8.8) | 0.74% | — | IBM Websphere Application Server | 11/6/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Websphere Application Server ND | 7/6/2021 | 17/6/2026 | IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435. | |
| Modificada | Alta (8.2) | 2.1% | — | IBM Websphere Application Server | 26/5/2021 | 17/6/2026 | IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793. | |
| Modificada | Alta (8.2) | 2.8% | — | IBM Websphere Application Server | 21/4/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649. | |
| Modificada | Alta (8.2) | 2.5% | — | IBM Websphere Application Server | 20/4/2021 | 17/6/2026 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Websphere Application Server | 8/4/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502. | |
| Modificada | Media (6.5) | 2.5% | — | IBM Websphere Application Server | 10/3/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml… | |
| Modificada | Alta (7.5) | 4.1% | — | IBM Websphere Application Server | 18/2/2021 | 17/6/2026 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883. | |
| Modificada | Alta (8.2) | 5.2% | — | IBM Websphere Application Server | 10/2/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882. | |
| Modificada | Crítica (9.8) | 7.2% | — | IBM MQIBM MQ ApplianceIBM Websphere MQ | 28/1/2021 | 17/6/2026 | IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509. | |
| Modificada | Alta (8.2) | 4.8% | — | IBM Websphere Application Server | 26/1/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025. | |
| Modificada | Media (5.3) | 0.98% | — | IBM Websphere Extreme Scale | 6/1/2021 | 17/6/2026 | IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 177932. | |
| Modificada | Media (6.5) | 2.6% | — | IBM Websphere Application Server | 28/10/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Modificada | Alta (7.5) | 2.0% | — | IBM Websphere Application Server | 1/10/2020 | 17/6/2026 | IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428. | |
| Modificada | Baja (3.3) | 0.33% | — | IBM Websphere Application Server | 30/9/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370. | |
| Modificada | Alta (7.5) | 2.8% | — | IBM Websphere Application Server | 21/9/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Websphere Application Server | 21/9/2020 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650. | |
| Modificada | Media (5.4) | 0.71% | — | IBM Websphere Application Server | 10/9/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433. | |
| Modificada | Media (6.1) | 0.92% | — | IBM Websphere Application ServerIBM Websphere Virtual Enterprise | 27/8/2020 | 17/6/2026 | IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured. | |
| Modificada | Crítica (9.8) | 8.5% | — | IBM Websphere Application Server | 13/8/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585. | |
| Modificada | Alta (8.8) | 0.41% | — | IBM Websphere Application Server | 3/8/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with… | |
| Modificada | Alta (8.8) | 13% | 💥 PoC | IBM Websphere Application Server | 17/7/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM MQIBM Websphere MQ | 16/6/2020 | 17/6/2026 | IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081. | |
| Modificada | Crítica (9.8) | 34% | — | IBM Websphere Application Server | 5/6/2020 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231. |