Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.9% | — | IBM Websphere Application Server | 5/6/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230. | |
| Modificada | Crítica (9.8) | 12% | — | IBM Websphere Application ServerIBM Websphere Virtual Enterprise | 5/6/2020 | 17/6/2026 | IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Websphere Application Server | 14/5/2020 | 17/6/2026 | IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964. | |
| Modificada | Media (5.4) | 0.62% | — | IBM Websphere Application Server | 6/5/2020 | 17/6/2026 | IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084. | |
| Modificada | Media (5.3) | 2.4% | — | Redhat Hibernate ValidatorIBM Websphere Application ServerRedhat Jboss Enterprise Application PlatformRedhat Satellite+3 | 6/5/2020 | 17/6/2026 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Websphere Application Server | 28/4/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID: 177841. | |
| Modificada | Alta (8.8) | 2.4% | — | IBM Websphere Application Server | 10/4/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929. | |
| Modificada | Media (6.1) | 0.82% | — | IBM Websphere Application Server | 2/4/2020 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (6.1) | 0.82% | — | IBM Websphere Application Server | 2/4/2020 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Alta (7.5) | 3.1% | 💥 PoC | IBM Websphere Application Server | 26/3/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984. | |
| Modificada | Media (5.5) | 0.32% | — | IBM MQIBM MQ ApplianceIBM Websphere MQ | 16/3/2020 | 17/6/2026 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. | |
| Modificada | Media (6.5) | 1.4% | — | IBM MQIBM MQ ApplianceIBM Websphere MQ | 16/3/2020 | 17/6/2026 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 170967. | |
| Modificada | Media (5.5) | 0.32% | — | IBM MQIBM MQ ApplianceIBM Websphere MQ | 16/3/2020 | 17/6/2026 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Websphere Service Registry AND Repository | 26/2/2020 | 17/6/2026 | IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 165593. | |
| Modificada | Media (6.5) | 1.8% | — | IBM Websphere Application Server | 5/2/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319. | |
| Modificada | Alta (7.2) | 1.6% | — | IBM Websphere Application Server | 4/2/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397. | |
| Modificada | Media (6.5) | 0.54% | — | IBM SDKIBM Websphere Application Server | 3/2/2020 | 17/6/2026 | IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted… | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Websphere Application Server | 31/1/2020 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125. | |
| Modificada | Alta (7.6) | 0.90% | — | Jenkins Websphere Deployer | 29/1/2020 | 17/6/2026 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Websphere MQ | 23/1/2020 | 16/6/2026 | IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability | |
| Modificada | Alta (7.1) | 0.51% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM. | |
| Modificada | Alta (8.8) | 0.69% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | |
| Modificada | Media (5.4) | 0.68% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Websphere Application Server | 10/12/2019 | 17/6/2026 | IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245. | |
| Modificada | Media (5.3) | 1.6% | — | IBM Websphere Application Server | 3/10/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177. |