Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.26% | — | IBM Marketing PlatformAI | 11/9/2026 | 22/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |
| Aplazada | Crítica (9.8) | 0.68% | — | ESI Technology AIM Line Marketing PlatformAI | 15/10/2024 | 17/6/2026 | AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Marketing Platform | 19/6/2019 | 17/6/2026 | IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906. | |
| Modificada | Alta (7.1) | 2.4% | — | IBM Marketing Platform | 7/12/2018 | 17/6/2026 | IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152855. | |
| Modificada | Alta (7.1) | 2.4% | — | IBM Marketing Platform | 7/12/2018 | 17/6/2026 | IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029. | |
| Modificada | Alta (8.8) | 1.0% | — | IBM Marketing PlatformIBM Marketing OperationsIBM Distributed Marketing | 22/5/2017 | 17/6/2026 | IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282. | |
| Modificada | Media (6.1) | 0.92% | — | IBM Marketing Platform | 5/5/2017 | 17/6/2026 | IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the… | |
| Modificada | Media (5.4) | 0.65% | — | IBM Marketing Platform | 17/4/2017 | 17/6/2026 | IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM X-Force ID: 110236. | |
| Modificada | Alta (8.8) | 1.1% | — | IBM Marketing Platform | 28/6/2016 | 17/6/2026 | SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | IBM Marketing Platform | 28/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Crítica (9.8) | 1.3% | — | IBM Marketing Platform | 28/6/2016 | 17/6/2026 | SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 0.96% | — | IBM Marketing Platform | 28/6/2014 | 17/6/2026 | SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Marketing Platform | 28/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6) | 0.95% | — | IBM Marketing Platform | 28/6/2014 | 17/6/2026 | IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection. | |
| Modificada | Media (4.9) | 0.85% | — | IBM Marketing Platform | 28/6/2014 | 17/6/2026 | IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection. |