Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.27% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 29/9/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 1/10/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | |
| Aplazada | Media (5.3) | 0.29% | — | Accessibe WEB AccessibilityAI | 19/2/2026 | 17/6/2026 | The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11. This is due to the `accessibe_render_js_in_footer()` function logging the complete plugin options array to the browser console on public pages, without restricting output… | |
| Aplazada | Media (5.9) | 0.17% | — | Ability INC WEB Accessibility With MAX AccessAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Stored XSS.This issue affects Web Accessibility with Max Access: from n/a through <= 2.1.0. | |
| Aplazada | Media (5.4) | 0.28% | — | Accessibe WEB AccessibilityAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Web Accessibility By accessiBe: from n/a through <= 2.10. | |
| Aplazada | Media (4.3) | 0.16% | — | WEB Accessibility BY AccessibeAI | 11/10/2025 | 30/9/2026 | The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due to missing nonce validation on multiple AJAX actions including accessibe_signup, accessibe_login, accessibe_license_trial, accessibe_modify_config, and… | |
| Analizada | Media (5.9) | 0.33% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 7/7/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques. | |
| Aplazada | Media (4.3) | 0.15% | — | Ability INC WEB Accessibility With MAX AccessAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Cross Site Request Forgery.This issue affects Web Accessibility with Max Access: from n/a through <= 2.0.9. | |
| Aplazada | Media (5.9) | 0.28% | — | Rachel Cherry Wa11y THE WEB Accessibility ToolboxAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry wA11y – The Web Accessibility Toolbox wa11y allows Stored XSS.This issue affects wA11y – The Web Accessibility Toolbox: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.30% | — | WEB Accessibility BY AccessibeAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Reflected XSS.This issue affects Web Accessibility By accessiBe: from n/a through <= 2.5. | |
| Modificada | Alta (8.2) | 0.61% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 18/7/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335. | |
| Modificada | Media (5.1) | 0.20% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336. | |
| Modificada | Media (6.5) | 0.25% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216. | |
| Modificada | Media (4.8) | 0.32% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251052. | |
| Modificada | Media (5.4) | 0.38% | — | Equalweb Accessibility Widget | 17/11/2022 | 17/6/2026 | EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js. | |
| Modificada | Media (6.1) | 0.56% | — | Fortinet Fortiauthenticator Agent FOR Microsoft Outlook WEB Access | 18/7/2022 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Rational Doors WEB Access | 16/5/2019 | 17/6/2026 | IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.5) | 23% | — | Microsoft Outlook WEB Access | 16/6/2016 | 17/6/2026 | Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange… | |
| Modificada | Alta (7.8) | 3.8% | — | Safenet-inc Safenet Authentication Service Outlook WEB Access Agent | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa. | |
| Modificada | Media (6.4) | 1.4% | — | Scalix WEB Access | 10/12/2014 | 17/6/2026 | XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request. | |
| Modificada | Media (4.3) | 1.1% | — | Scalix WEB Access | 9/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.4% | — | EMC Applicationxtender DesktopEMC Applicationxtender WEB Access .net | 26/8/2012 | 16/6/2026 | EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Cyber-ark Password Vault WEB Access | 5/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.2% | — | IBM Rational Doors WEB Access | 7/7/2011 | 16/6/2026 | The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login. | |
| Modificada | Alta (10) | 1.8% | — | IBM Rational Doors WEB Access | 7/7/2011 | 16/6/2026 | IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors. |