Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.98% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309. | |
| Modificada | Alta (8.8) | 1.1% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force ID: 196308. | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored in memory. IBM X-Force ID: 196304. | |
| Modificada | Media (5.9) | 0.67% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195361. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195357. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195037. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195036. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195035. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195034. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195033. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195032. | |
| Modificada | Alta (7.5) | 0.71% | — | IBM Cloud PAK FOR Applications | 13/7/2021 | 17/6/2026 | IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031. |