Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa LMS | 31/3/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference… | |
| Modificada | Media (6.5) | 1.8% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | |
| Modificada | Alta (7.6) | 0.97% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Modificada | Media (5.4) | 0.88% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Modificada | Alta (7.6) | 0.97% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Modificada | Media (5.4) | 0.55% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (5.7) | 1.6% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Baja (3.3) | 0.31% | — | IBM Kenexa LMS | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 1.8% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Modificada | Media (4.3) | 0.94% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user. | |
| Modificada | Media (5.4) | 0.64% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. | |
| Modificada | Media (6.5) | 1.8% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (8.8) | 2.2% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 0.77% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users. | |
| Modificada | Media (6.3) | 0.80% | — | IBM Kenexa LMS ON Cloud | 1/2/2017 | 17/6/2026 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. |