Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.27% | — | IBM Storage Defender Resiliency Service | 8/12/2025 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. | |
| Analizada | Alta (7.5) | 0.23% | — | IBM Storage Defender Resiliency Service | 16/4/2025 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Alta (7.5) | 0.26% | — | IBM Storage Defender | 27/1/2025 | 17/6/2026 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.7) | 0.54% | — | IBM Storage Defender Resiliency Service | 18/12/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Storage Defender Resiliency Service | 18/12/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. | |
| Analizada | Media (4.9) | 0.35% | — | IBM Storage Defender Resiliency Service | 18/12/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Storage Defender | 25/9/2024 | 17/6/2026 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. | |
| Modificada | Alta (7.5) | 0.41% | — | IBM Storage Defender Resiliency Service | 28/6/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869. | |
| Modificada | Media (6.5) | 0.25% | — | IBM Storage Defender | 28/6/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678. | |
| Analizada | Media (6.8) | 0.27% | — | IBM Storage Defender Resiliency Service | 12/4/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986. | |
| Modificada | Alta (7.8) | 0.13% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749. | |
| Modificada | Media (5.5) | 0.15% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748. | |
| Modificada | Alta (7.2) | 0.42% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783. | |
| Modificada | Media (5.4) | 0.33% | — | IBM Storage Defender Data Protect | 19/1/2024 | 17/6/2026 | IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… |