Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.54%—IBM Kenexa LMS31/3/201717/6/2026
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference…
ModificadaMedia (6.5)1.8%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
ModificadaAlta (8.8)1.9%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ModificadaAlta (8.8)1.9%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ModificadaAlta (7.6)0.97%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
ModificadaMedia (5.4)0.88%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
ModificadaAlta (7.6)0.97%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
ModificadaMedia (5.4)0.55%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (5.7)1.6%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
ModificadaMedia (5.4)0.54%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaBaja (3.3)0.31%—IBM Kenexa LMS1/2/201717/6/2026
IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
ModificadaMedia (5.4)0.54%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (6.5)1.8%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
ModificadaMedia (4.3)0.94%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
ModificadaMedia (5.4)0.64%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
ModificadaMedia (6.5)1.8%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
ModificadaMedia (5.4)0.54%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaAlta (8.8)2.2%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ModificadaMedia (5.4)0.54%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (4.3)0.77%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.
ModificadaMedia (6.3)0.80%—IBM Kenexa LMS ON Cloud1/2/201717/6/2026
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.