Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.34%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
AnalizadaAlta (7.2)1.6%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
AnalizadaAlta (7.2)0.82%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
AnalizadaMedia (5.4)0.21%—IBM Aspera Faspex10/3/202617/6/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
AnalizadaMedia (5.4)0.21%—IBM Aspera Faspex10/3/202617/6/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.20%—IBM Aspera Faspex26/12/20255/10/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (4.3)0.24%—IBM Aspera Faspex26/12/20255/10/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
AnalizadaBaja (3.8)0.22%—IBM Aspera Faspex26/12/20255/10/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
AnalizadaMedia (4.3)0.23%—IBM Aspera Faspex9/10/202517/6/2026
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
AnalizadaMedia (4.9)0.32%—IBM Aspera Faspex9/10/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
AnalizadaMedia (5.3)0.22%—IBM Aspera Faspex9/10/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
AnalizadaMedia (6.5)0.21%—IBM Aspera Faspex31/7/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
AnalizadaMedia (6.5)0.26%—IBM Aspera Faspex31/7/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
AnalizadaMedia (6.1)0.26%—IBM Aspera Faspex22/5/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaAlta (8.8)0.34%—IBM Aspera Faspex22/5/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
AnalizadaAlta (8.8)0.34%—IBM Aspera Faspex22/5/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
AnalizadaMedia (5.4)0.28%—IBM Aspera Faspex13/4/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.3)0.30%—IBM Aspera Faspex29/1/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
AnalizadaMedia (4.9)0.27%—IBM Aspera Faspex29/1/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
AnalizadaCrítica (9.8)0.33%—IBM Aspera Faspex29/1/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaCrítica (9.8)0.33%—IBM Aspera Faspex29/1/202517/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaBaja (3.3)0.06%—IBM Aspera Faspex11/12/202417/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
AnalizadaAlta (8.1)0.35%—IBM Aspera Faspex5/9/202417/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
AnalizadaAlta (7.1)0.31%—IBM Aspera Faspex5/9/202417/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
AnalizadaMedia (6.5)0.37%—IBM Aspera Faspex5/9/202417/6/2026
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.