Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Doors NextIBM Engineering Lifecycle ManagementIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test Management+5 | 4/3/2021 | 17/6/2026 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459. | |
| Modificada | Alta (7.8) | 0.43% | — | Conquer-once Project Conquer-once | 26/1/2021 | 17/6/2026 | An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sync type, leading to memory corruption. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+9 | 8/1/2021 | 17/6/2026 | IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Doors NextIBM Engineering Requirements Management Doors NextIBM Engineering Test ManagementIBM Engineering Workflow Management+6 | 2/9/2020 | 17/6/2026 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Doors NextIBM Engineering Requirements Management Doors NextIBM Engineering Test ManagementIBM Engineering Workflow Management+6 | 2/9/2020 | 17/6/2026 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182397. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Doors NextIBM Engineering Requirements Management Doors NextIBM Engineering Test ManagementIBM Engineering Workflow Management+6 | 2/9/2020 | 17/6/2026 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122. | |
| Modificada | Media (6.1) | 0.81% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering Lifecycle ManagerIBM Engineering Test Management+6 | 16/7/2020 | 17/6/2026 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Engineering Workflow ManagementIBM Rational Team Concert | 16/7/2020 | 17/6/2026 | IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172887. | |
| Modificada | Media (4.3) | 0.65% | — | Jenkins Team Concert | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.80% | — | Jenkins Team Concert | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.64% | — | Jenkins Team Concert | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 1.6% | — | Once Cell Project Once Cell | 9/9/2019 | 17/6/2026 | An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 PoC | Realization Concerto Critical Chain Planner | 12/7/2019 | 17/6/2026 | Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter. |