Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.4% | — | Akeneo Product Information Management | 9/12/2022 | 17/6/2026 | Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the versions aforementioned provides… | |
| Modificada | Crítica (9.8) | 3.9% | — | Akeneo Product Information Management | 17/7/2017 | 17/6/2026 | Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaborative ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote… | |
| Modificada | Media (4) | 0.80% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaborative Server | 22/12/2014 | 17/6/2026 | The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's… | |
| Modificada | Media (5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain… | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 0.69% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Infosphere Master Data ManagementIBM Infosphere Master Data Management Server FOR Product Information Management | 17/8/2014 | 17/6/2026 | SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL… | |
| Modificada | Baja (3.5) | 0.65% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management | 1/8/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via… | |
| Modificada | Media (6.3) | 1.1% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or… | |
| Modificada | Media (6.8) | 0.57% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 4/2/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.9) | 0.50% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 19/12/2013 | 16/6/2026 | Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaboration Server | 27/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 21/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Media (6) | 0.93% | — | IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management | 21/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing… |