Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 8.1% | — | IBM DominoIBM NotesSymantec Data Loss Prevention EndpointSymantec Data Loss Prevention Enforce/detection Servers+3 | 21/2/2020 | 16/6/2026 | Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus… | |
| Modificada | Alta (7.8) | 0.48% | — | IBM DominoIBM Notes | 20/12/2018 | 17/6/2026 | IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687. | |
| Modificada | Alta (7) | 0.30% | — | Samsung Notes | 24/9/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of… | |
| Modificada | Media (6.5) | 1.9% | — | Moderator LOG Notes Project Moderator LOG Notes | 24/8/2018 | 17/6/2026 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF. | |
| Modificada | Alta (7) | 0.27% | — | IBM Lotus Notes | 16/7/2018 | 16/6/2026 | The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371. | |
| Modificada | Media (5.4) | 0.57% | — | Moderator LOG Notes Project Moderator LOG Notes | 28/5/2018 | 17/6/2026 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea. | |
| Modificada | Media (6.5) | 0.97% | — | Admin Notes Project Admin Notes | 21/5/2018 | 17/6/2026 | An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action. | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Alta (7.8) | 2.2% | — | IBM Notes | 14/3/2018 | 17/6/2026 | IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565. | |
| Modificada | Alta (7.8) | 2.5% | — | IBM Notes | 14/3/2018 | 17/6/2026 | IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563. | |
| Modificada | Alta (7.8) | 0.37% | — | IBM NotesIBM Client Application Access | 19/2/2018 | 17/6/2026 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM NotesIBM Client Application Access | 19/2/2018 | 17/6/2026 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138709. | |
| Modificada | Alta (7.8) | 0.37% | — | IBM NotesIBM Client Application Access | 19/2/2018 | 17/6/2026 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708. | |
| Modificada | Media (5.3) | 0.41% | — | IBM NotesIBM Client Application Access | 13/2/2018 | 17/6/2026 | IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807. | |
| Modificada | Alta (7.8) | 0.34% | — | IBM NotesIBM Client Application Access | 13/2/2018 | 17/6/2026 | IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633. | |
| Modificada | Alta (7.8) | 1.1% | — | IBM NotesIBM Client Application Access | 13/2/2018 | 17/6/2026 | IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Inotes | 13/12/2017 | 17/6/2026 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 29% | — | IBM Inotes | 5/9/2017 | 17/6/2026 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371. | |
| Modificada | Media (6.5) | 30% | — | IBM InotesIBM Expeditor | 5/9/2017 | 17/6/2026 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370. | |
| Modificada | Media (6.1) | 0.97% | — | IBM Inotes | 3/8/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062. | |
| Modificada | Media (6.1) | 0.98% | — | IBM Inotes | 31/7/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234. | |
| Modificada | Media (5.7) | 1.3% | — | IBM Inotes | 12/6/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854. |