Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
En análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202630/9/2026
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
Pendiente de análisisMedia (6.5)0.25%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI14/9/202616/9/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this…
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI14/9/202616/9/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL…
Pendiente de análisisMedia (6.5)0.25%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI14/9/202616/9/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this…
AplazadaMedia (6.5)0.39%—Webliberty Simple SpoilerAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler allows Stored XSS.This issue affects Simple Spoiler: from n/a through <= 1.4.
AnalizadaAlta (7.3)0.56%—Webliberty Simple Spoiler14/9/202417/6/2026
The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary…
AplazadaMedia (5.9)0.26%—Webliberty Simple SpoilerAI3/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2.
ModificadaCrítica (9.8)0.46%—IBM Websphere Application Server Liberty25/10/202317/6/2026
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
ModificadaAlta (8.8)0.85%—IBM Open LibertyIBM Websphere Application Server8/7/202217/6/2026
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
ModificadaMedia (6.5)0.64%—IBM Open LibertyIBM Websphere Application Server17/5/202217/6/2026
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaBaja (3.3)0.35%—IBM Liberty11/1/201817/6/2026
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.
ModificadaAlta (7.5)3.2%—IBM Liberty24/10/201717/6/2026
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.
ModificadaMedia (4.3)1.5%—IBM Liberty18/3/201517/6/2026
The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)1.5%—French National Commission ON Informatics AND Liberty Cookieviz6/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in json.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz allows remote we servers to inject arbitrary web script or HTML via the max_date parameter.
ModificadaAlta (7.5)1.7%—French National Commission ON Informatics AND Liberty Cookieviz6/11/201417/6/2026
SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter.