Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.3% | — | IBM Rational Doors Next GenerationIBM Rational Requirements ComposerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5.5) | 1.4% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5) | 1.7% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+3 | 12/9/2014 | 17/6/2026 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 4/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.9) | 0.95% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 4/3/2014 | 17/6/2026 | Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 4/3/2014 | 17/6/2026 | Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Lythgoes THE Next Generation OF Genealogy Sitebuilding | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchform.php in The Next Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Next Generation Software Virtual DJ (vdj) | 6/9/2007 | 16/6/2026 | Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. | |
| Modificada | Media (5) | 1.4% | — | Next Generation Image Gallery | 5/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Alta (7.8) | 4.9% | — | Checkpoint Check PointCheckpoint ExpressCheckpoint Firewall-1Checkpoint Vpn-1+1 | 18/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666,… | |
| Modificada | Alta (10) | 5.0% | — | Checkpoint Firewall-1Checkpoint Next GenerationCheckpoint Ng-aiCheckpoint Vpn-1 | 7/7/2004 | 16/6/2026 | Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation. | |
| Modificada | Baja (3.6) | 0.29% | — | Bill ABT Next Generation Posix Threading | 31/12/2002 | 16/6/2026 | Next Generation POSIX Threading (NGPT) 1.9.0 uses a filesystem-based shared memory entry, which allows local users to cause a denial of service or in threaded processes or spoof files via unknown methods. | |
| Modificada | Alta (7.5) | 1.6% | — | Checkpoint Check Point VPNCheckpoint Firewall-1Checkpoint Next Generation | 12/8/2002 | 16/6/2026 | Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file. |