Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.40%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
AnalizadaAlta (8.8)0.42%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
AnalizadaAlta (7.5)0.10%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.
AnalizadaAlta (8.1)0.83%—IBM Engineering Systems Design Rhapsody22/11/202417/6/2026
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.
ModificadaAlta (8.8)0.59%—IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+327/10/202117/6/2026
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
ModificadaMedia (5.4)0.62%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+812/4/202117/6/2026
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.
ModificadaAlta (7.5)0.72%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+812/4/202117/6/2026
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
ModificadaMedia (4.3)0.64%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+812/4/202117/6/2026
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
ModificadaMedia (5.4)0.62%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+812/4/202117/6/2026
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.
ModificadaMedia (5.4)0.66%—IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+727/1/202117/6/2026
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963.
ModificadaMedia (5.4)0.66%—IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+727/1/202117/6/2026
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
ModificadaMedia (5.4)0.66%—IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+727/1/202117/6/2026
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.
ModificadaMedia (5.4)0.82%—IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+727/1/202117/6/2026
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID:…
ModificadaMedia (5.4)0.66%—IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+727/1/202117/6/2026
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.
ModificadaMedia (5.4)0.56%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+98/1/202117/6/2026
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.
ModificadaMedia (5.4)0.56%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+98/1/202117/6/2026
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.
ModificadaMedia (5.4)0.56%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+98/1/202117/6/2026
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.
ModificadaMedia (4.3)0.99%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+98/1/202117/6/2026
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.
ModificadaMedia (4.3)0.99%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering InsightsIBM Engineering Lifecycle Management+98/1/202117/6/2026
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.
ModificadaMedia (5.4)0.56%—IBM Engineering Workflow ManagementIBM Rational Rhapsody Design Manager4/8/202017/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435.
ModificadaMedia (4.3)0.99%—IBM Engineering Test ManagementIBM Rational Rhapsody Design Manager4/8/202017/6/2026
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.
ModificadaMedia (5.4)0.56%—IBM Collaborative Lifecycle ManagementIBM Doors NextIBM Engineering Lifecycle ManagerIBM Engineering Test Management+616/7/202017/6/2026
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.
ModificadaAlta (7.5)3.4%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+327/6/201917/6/2026
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 159883.
ModificadaMedia (5.4)0.67%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+327/6/201917/6/2026
IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
ModificadaMedia (5.4)0.67%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+327/6/201917/6/2026
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…