Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.11% | — | HCL Workload SchedulerAI | 11/12/2025 | 1/10/2026 | HCL Workload Scheduler stores user credentials in plain text which can be read by a local user. | |
| Analizada | Media (5.5) | 0.15% | — | IBM Workload Scheduler | 26/11/2024 | 17/6/2026 | IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user. | |
| Modificada | Crítica (9.1) | 1.3% | — | IBM Tivoli Workload Scheduler | 3/2/2023 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233975. | |
| Modificada | Crítica (9.1) | 1.4% | — | IBM Tivoli Workload Scheduler | 3/2/2023 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328. | |
| Modificada | Alta (7.1) | 0.19% | — | IBM Workload Scheduler | 10/8/2022 | 17/6/2026 | IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 221187. | |
| Modificada | Media (5.3) | 0.25% | — | IBM Tivoli Workload Scheduler | 9/8/2021 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 194599. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Workload Scheduler | 11/6/2020 | 17/6/2026 | IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179160. | |
| Modificada | Media (5.4) | 0.68% | — | IBM Tivoli Workload Scheduler | 10/3/2020 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168508. | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Tivoli Workload Scheduler | 16/10/2019 | 17/6/2026 | IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file system, which could allow the attacker to gain root privileges. IBM X-Force ID: 155997. | |
| Modificada | Alta (7.8) | 0.28% | — | IBM Tivoli Workload Scheduler | 14/3/2018 | 17/6/2026 | IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Tivoli Workload Scheduler | 13/12/2017 | 17/6/2026 | IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638. |