Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application ServerIBM Websphere Message Broker | 29/5/2013 | 16/6/2026 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a… | |
| Modificada | Baja (2.6) | 1.1% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string. | |
| Modificada | Media (5) | 1.4% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.8% | — | IBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges | 31/1/2013 | 16/6/2026 | InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors. | |
| Modificada | Alta (9.3) | 1.3% | — | IBM Infosphere Import Export ManagerIBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges | 31/1/2013 | 16/6/2026 | Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (6.9) | 0.37% | — | IBM Websphere Message Broker | 5/12/2012 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Site2nite BIG Truck Broker | 1/12/2010 | 16/6/2026 | SQL injection vulnerability in news_default.asp in Site2Nite Big Truck Broker allows remote attackers to execute arbitrary SQL commands via the txtSiteId parameter. | |
| Modificada | Alta (10) | 1.2% | — | Chris Buccella Small Footprint CIM Broker | 14/9/2009 | 16/6/2026 | Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors. | |
| Modificada | Media (5) | 2.2% | — | Microfocus Visibroker | 31/8/2009 | 16/6/2026 | osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet with a large string length value to UDP port 14000, which triggers a memory allocation failure that is not properly handled. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Microfocus Visibroker | 31/8/2009 | 16/6/2026 | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Websphere Message Broker | 13/2/2009 | 16/6/2026 | IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs. | |
| Modificada | Media (6.9) | 0.42% | — | Symark Powerbroker | 28/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises. | |
| Modificada | Media (5) | 1.2% | — | Hitachi Tpbroker Object Transaction Monitor | 9/10/2007 | 16/6/2026 | The TSC Domain Manager in Hitachi TPBroker Object Transaction Monitor and Cosminexus TPBroker Object Transaction Monitor 01-00 through 03-00 might allow attackers to cause a denial of service (crash) via invalid messages. | |
| Modificada | Media (4.3) | 1.5% | — | Hitachi Cosminexus DabrokerHitachi Dabroker | 28/8/2007 | 16/6/2026 | Unspecified vulnerability in Hitachi DABroker before 03-02-/D and Cosminexus DABroker before 02-04-/C and 03-05-/E allows remote attackers to cause a denial of service (connection prevention) by sending "data unexpectedly through a port." | |
| Modificada | Alta (7.8) | 1.9% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus TpbrokerHitachi TpbrokerHitachi Tpbroker Developer+1 | 9/7/2007 | 16/6/2026 | Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request. | |
| Modificada | Media (5) | 1.7% | — | Transsoft Broker FTP Server | 23/11/2004 | 16/6/2026 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Transsoft Broker FTP Server | 23/11/2004 | 16/6/2026 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection. | |
| Modificada | Alta (10) | 5.3% | — | Transsoft Broker FTP Server | 26/7/2002 | 16/6/2026 | Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters. | |
| Modificada | Media (5) | 1.7% | — | Transsoft Broker FTP Server | 20/9/2001 | 16/6/2026 | Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename). | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | Transsoft Broker FTP Server | 20/9/2001 | 16/6/2026 | Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command. | |
| Modificada | Alta (7.5) | 3.3% | — | Transsoft Broker FTP Server | 2/7/2001 | 16/6/2026 | Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. | |
| Modificada | Media (6.4) | 1.7% | — | Transsoft Broker FTP Server | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Transsoft Broker FTP Server | 9/1/2001 | 16/6/2026 | Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command. |