Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.77% | — | IBM Integration BUSIBM Websphere Message Broker | 15/2/2017 | 17/6/2026 | IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM… | |
| Modificada | Media (5.3) | 1.0% | — | IBM Websphere Message Broker | 1/2/2017 | 17/6/2026 | The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker. | |
| Modificada | Baja (3.3) | 0.28% | — | IBM Integration BUSIBM Websphere Message Broker | 1/2/2017 | 17/6/2026 | IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files. | |
| Modificada | Media (5.4) | 1.7% | — | Oracle Retail Order Broker Cloud Service | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Order Broker component in Oracle Retail Applications 15.0 allows remote attackers to affect confidentiality and integrity via vectors related to System Administration. | |
| Modificada | Alta (7.6) | 2.3% | — | Oracle Retail Order Broker | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Order Broker component in Oracle Retail Applications 5.1 and 5.2 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to System Administration. | |
| Modificada | Baja (3.1) | 1.7% | — | Oracle Enterprise Communications Broker | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3514. | |
| Modificada | Alta (7.5) | 3.8% | — | Oracle Enterprise Communications Broker | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Media (6.5) | 2.7% | — | Oracle Enterprise Communications Broker | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3516. | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Media (5.3) | 1.5% | — | IBM Integration BUSIBM Websphere Message Broker | 2/7/2016 | 17/6/2026 | The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace. | |
| Modificada | Crítica (9.1) | 8.1% | — | Apache Qpid Broker-j | 1/6/2016 | 17/6/2026 | The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging. | |
| Modificada | Media (5.9) | 7.8% | — | Apache Qpid Broker-j | 1/6/2016 | 17/6/2026 | PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception. | |
| Modificada | Alta (7.5) | 2.0% | — | Oracle Retail Order Broker Cloud Service | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Order Broker Cloud Service component in Oracle Retail Applications 4.0 and 4.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to System Administration. | |
| Modificada | Media (5.3) | 1.9% | — | IBM Integration BUSIBM Websphere Message Broker | 11/1/2016 | 17/6/2026 | IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors. | |
| Modificada | Baja (3.2) | 0.33% | — | IBM Websphere Message BrokerIBM Integration BUS | 26/10/2015 | 17/6/2026 | IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command. | |
| Modificada | Baja (3.5) | 0.87% | — | IBM Integration BUSIBM Websphere Message Broker | 23/8/2015 | 17/6/2026 | IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Crítica (9.8) | 41% | — | Apache GroovyOracle Health Sciences Clinical Development CenterOracle Retail Order Broker Cloud ServiceOracle Retail Service Backbone+2 | 13/8/2015 | 17/6/2026 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Videoscape Distribution Suite Service BrokerCisco Videoscape Distribution Suite FOR Internet Streaming | 16/7/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a denial of service (device reload) via a crafted HTTP… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Websphere Message BrokerIBM Integration BUS | 28/6/2015 | 17/6/2026 | IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection… | |
| Modificada | Media (5) | 56% | — | Oracle Enterprise Communications BrokerEmbedthis AppwebJuniper Junos | 31/3/2015 | 17/6/2026 | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,". | |
| Modificada | Media (5) | 1.4% | — | IBM Integration BUSIBM Websphere Message Broker | 2/2/2015 | 17/6/2026 | The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault. | |
| Modificada | Media (5.4) | 0.29% | — | Gunbroker.com | 2/10/2014 | 17/6/2026 | The GunBroker.com (aka com.gunbroker.android) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Message BrokerIBM Integration BUS | 18/9/2014 | 17/6/2026 | The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page. | |
| Modificada | Media (4.3) | 2.8% | — | IBM Websphere Message Broker | 19/10/2013 | 16/6/2026 | The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities. | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… |