Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.17% | — | Hcltech Appscan Source | 31/10/2024 | 17/6/2026 | HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. | |
| Modificada | Media (4.8) | 0.52% | — | Hcltech Appscan Source | 18/12/2019 | 17/6/2026 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | |
| Modificada | Alta (7.1) | 0.80% | — | Hcltech Appscan Source | 25/9/2019 | 17/6/2026 | HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in… | |
| Modificada | Crítica (9.8) | 5.0% | — | IBM Rational Appscan SourceIBM Security Appscan Source | 12/4/2018 | 17/6/2026 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721. | |
| Modificada | Media (5.3) | 1.0% | — | IBM Security Appscan Source | 1/2/2017 | 17/6/2026 | IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. | |
| Modificada | Media (4.4) | 0.21% | — | IBM Security Appscan Source | 1/2/2017 | 17/6/2026 | IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily. | |
| Modificada | Alta (8.1) | 1.4% | — | IBM Appscan Source | 1/12/2016 | 17/6/2026 | IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Rational Appscan SourceIBM Security Appscan Source | 29/12/2014 | 17/6/2026 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Security AppscanIBM Security Appscan Source | 23/12/2014 | 17/6/2026 | IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (5.5) | 1.5% | — | IBM Security AppscanIBM Security Appscan Source | 23/12/2014 | 17/6/2026 | IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to write to arbitrary folders, and consequently execute arbitrary commands, via a modified… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Security AppscanIBM Security Appscan Source | 23/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a… | |
| Modificada | Alta (9.3) | 3.6% | — | IBM Security AppscanIBM Security Appscan Source | 23/12/2014 | 17/6/2026 | IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to execute arbitrary code via a crafted executable file in an archive. | |
| Modificada | Baja (1.8) | 0.49% | — | IBM Security Appscan Source | 26/10/2014 | 17/6/2026 | The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port. | |
| Modificada | Alta (7.2) | 0.37% | — | IBM Security Appscan Source | 12/8/2014 | 17/6/2026 | Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, and 9.0 through 9.0.0.1 allows local users to gain privileges by executing a crafted service. | |
| Modificada | Media (4.3) | 0.63% | — | IBM Security Appscan Source | 8/6/2014 | 17/6/2026 | IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (5) | 1.2% | — | IBM Security Appscan Source | 20/6/2012 | 16/6/2026 | The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Security Appscan SourceIBM Spss Data Collection | 20/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5.8) | 1.8% | — | IBM Security Appscan SourceIBM Spss Data Collection | 20/6/2012 | 16/6/2026 | Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |