Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.25% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. IBM X-Force ID: 197980. | |
| Modificada | Baja (2.7) | 0.97% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973 | |
| Modificada | Media (5.3) | 0.94% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972. | |
| Modificada | Alta (7.5) | 0.71% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969 | |
| Modificada | Media (4.9) | 0.65% | — | IBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Security Access ManagerIBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Security Verify | 25/6/2021 | 17/6/2026 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (5.4) | 0.83% | — | IBM Security Verify | 25/6/2021 | 17/6/2026 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache… | |
| Modificada | Media (4.9) | 0.90% | — | IBM Security Verify | 25/6/2021 | 17/6/2026 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation.. IBM X-Force ID: 199396. | |
| Modificada | Alta (7.8) | 0.17% | — | IBM Security Verify Privilege Manager | 25/6/2021 | 17/6/2026 | IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919. | |
| Modificada | Alta (7.8) | 0.29% | — | IBM Security Verify Privilege Manager | 25/6/2021 | 17/6/2026 | IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute arbitrary code on the system or cause the system to crash. IBM X-Force ID: 184917. | |
| Modificada | Alta (7.8) | 1.1% | — | IBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges. | |
| Modificada | Media (5.3) | 1.0% | — | IBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system. IBM X-Force ID: 199398. | |
| Modificada | Alta (7.5) | 2.5% | — | IBM Application GatewayIBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Application GatewayIBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Security Verify Bridge | 3/3/2021 | 17/6/2026 | IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618. | |
| Modificada | Media (5.9) | 0.81% | — | IBM Security Verify Bridge | 3/3/2021 | 17/6/2026 | IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617. | |
| Modificada | Alta (7.5) | 0.94% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 198192. | |
| Modificada | Alta (8.1) | 0.45% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191. | |
| Modificada | Media (5.3) | 0.71% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190. | |
| Modificada | Alta (7.5) | 0.99% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID:… | |
| Modificada | Media (5.5) | 0.19% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187. | |
| Modificada | Alta (7.5) | 0.73% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185. | |
| Modificada | Media (4.9) | 0.52% | — | IBM Security Verify Information Queue | 12/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184. | |
| Modificada | Alta (7.5) | 0.78% | — | IBM Security Verify Information Queue | 11/2/2021 | 17/6/2026 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183. |