Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.52% | — | Ancorathem Great LotusAIPHPAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Great Lotus great-lotus allows PHP Local File Inclusion.This issue affects Great Lotus: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.9) | 0.14% | — | Lotus CarsAIGoogle AndroidAI | 14/8/2025 | 5/7/2026 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exposure. | |
| Aplazada | Media (6.5) | 0.33% | — | Lotus Cars Android APPAI | 14/8/2025 | 5/7/2026 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse. | |
| Modificada | Alta (7.8) | 0.48% | — | Lotus 1-2-3 Project Lotus 1-2-3 | 5/9/2022 | 17/6/2026 | 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from… | |
| Modificada | Alta (7.5) | 0.98% | — | Filecoin Lotus | 15/4/2021 | 17/6/2026 | Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized", and "compressed", meaning that BLS signatures can be provided as either of 2 unique byte arrays. Lotus block… | |
| Modificada | Alta (8.8) | 11% | — | Lotus Core CMS Project Lotus Core CMS | 5/2/2020 | 17/6/2026 | Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter. | |
| Modificada | Alta (7) | 0.27% | — | IBM Lotus Notes | 16/7/2018 | 16/6/2026 | The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531. | |
| Modificada | Media (5.4) | 0.64% | — | IBM Lotus Protector FOR Mail Security | 1/12/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.80% | — | IBM Lotus Inotes | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS. | |
| Modificada | Alta (7.5) | 5.1% | — | IBM Lotus NotesIBM Lotus DominoIBM Websphere Real Time | 12/8/2014 | 17/6/2026 | Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Lotus DominoIBM Lotus Inotes | 9/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE. | |
| Modificada | Media (5) | 4.2% | — | IBM Lotus DominoIBM Lotus Notes | 23/4/2014 | 17/6/2026 | IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W. | |
| Modificada | Alta (7.1) | 1.6% | — | IBM Lotus Protector FOR Mail Security | 25/3/2014 | 17/6/2026 | The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.6% | — | IBM Lotus Protector FOR Mail Security | 25/3/2014 | 17/6/2026 | The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (6.8) | 0.57% | — | IBM Lotus Protector FOR Mail Security | 25/3/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Lotus Protector FOR Mail Security | 25/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.8% | — | IBM Lotus Domino | 6/2/2014 | 17/6/2026 | The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, aka SPR KLYH9F4S2Z. | |
| Modificada | Alta (7.5) | 4.0% | — | IBM Lotus Quickr FOR Domino | 29/1/2014 | 17/6/2026 | Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6748. | |
| Modificada | Alta (7.5) | 3.1% | — | IBM Lotus Quickr FOR Domino | 29/1/2014 | 17/6/2026 | Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6749. | |
| Modificada | Baja (2.6) | 0.90% | — | IBM Lotus DominoIBM Lotus Inotes | 21/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP. | |
| Modificada | Baja (2.1) | 0.73% | — | IBM Lotus DominoIBM Lotus Inotes | 21/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Lotus DominoIBM Lotus Inotes | 21/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP. | |
| Modificada | Baja (2.9) | 0.53% | — | IBM Lotus Sametime | 9/11/2013 | 16/6/2026 | The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Lotus Sametime | 9/11/2013 | 16/6/2026 | The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Lotus Sametime | 9/11/2013 | 16/6/2026 | The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges. |