Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.8)0.15%—IBM Aspera Enterprise WebappsAI10/9/202611/9/2026
IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
AnalizadaAlta (7.3)0.17%—IBM Aspera30/7/202613/8/2026
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
AnalizadaAlta (8.2)0.34%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
AnalizadaCrítica (9.3)0.45%—IBM Aspera28/7/202613/8/2026
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
AnalizadaAlta (7.2)1.6%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
AnalizadaAlta (7.2)0.82%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
AnalizadaMedia (6.5)0.45%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage…
AnalizadaAlta (7.5)0.48%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd…
AnalizadaAlta (8.8)0.61%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute…
AnalizadaCrítica (9.8)0.94%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service…
ModificadaCrítica (9.1)0.50%—IBM Aspera High-speed Transfer Server FOR Cloud PAK FOR Integration27/5/202617/6/2026
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.
AnalizadaMedia (6.5)0.33%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
AnalizadaMedia (6.1)0.24%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (5.4)0.20%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
AnalizadaMedia (5.4)0.19%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (6.5)0.18%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
AnalizadaAlta (7.5)0.20%—IBM Aspera Shares1/4/202630/9/2026
IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
AnalizadaMedia (5.3)0.24%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
AnalizadaMedia (4.9)0.42%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
AnalizadaMedia (4.3)0.27%—IBM Aspera Console16/3/202617/6/2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
AnalizadaMedia (5.4)0.17%—IBM Aspera Orchestrator10/3/202617/6/2026
IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
AnalizadaMedia (5.4)0.21%—IBM Aspera Faspex10/3/202617/6/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
AnalizadaMedia (5.4)0.21%—IBM Aspera Faspex10/3/202617/6/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.5)0.33%—IBM Aspera Orchestrator10/3/202617/6/2026
IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
AnalizadaAlta (7.5)0.17%—IBM Aspera Faspio Gateway3/3/202617/6/2026
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information