Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

188 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.12%—Forcepoint Next Generation Firewall11/3/202617/6/2026
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.
ModificadaCrítica (9.8)2.4%—Epati Antikor Next Generation Firewall25/2/202617/6/2026
Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.
AplazadaMedia (5.3)0.36%—Hillstone Networks Hillstone Next Generation FirewallAI12/3/202517/6/2026
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.
AnalizadaMedia (5.5)0.42%—Sipwise Next Generation Communication Platform10/4/202417/6/2026
An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
AnalizadaBaja (3.1)0.46%—Sipwise Next Generation Communication Platform10/4/202417/6/2026
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.
AplazadaMedia (6.1)0.31%—Forcepoint Next Generation Firewall Security Management CenterAI4/3/202417/6/2026
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall…
ModificadaAlta (8.8)0.99%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with…
ModificadaCrítica (9.1)0.56%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
ModificadaCrítica (9.8)0.42%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
ModificadaAlta (7.7)0.47%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
ModificadaAlta (8.8)0.73%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and…
ModificadaAlta (8.8)0.59%—Tngsitebuilding THE Next Generation OF Genealogy Sitebuilding8/6/202217/6/2026
A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to 11.1.0. This issue affects some unknown processing of the file /timeline2.php. The manipulation of the argument primaryID leads to sql injection. The attack may be initiated remotely. The exploit…
ModificadaAlta (8.1)1.9%—Jenkins Warnings Next Generation12/1/202217/6/2026
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.
ModificadaCrítica (9.8)2.7%—Npmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora13/11/202117/6/2026
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact…
ModificadaAlta (8.8)0.59%—IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+327/10/202117/6/2026
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
ModificadaMedia (6.5)0.56%—IBM Engineering Lifecycle OptimizationIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next Generation+227/10/202117/6/2026
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
ModificadaAlta (7.5)0.98%—IBM Engineering Lifecycle OptimizationIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next Generation+227/10/202117/6/2026
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle OptimizationIBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle Manager+127/10/202117/6/2026
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle OptimizationIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next Generation+227/10/202117/6/2026
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.
ModificadaAlta (7.5)0.93%—Forcepoint Next Generation Firewall4/10/202117/6/2026
Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerability, if HTTP User Response has been configured.
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+528/7/202117/6/2026
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.
ModificadaMedia (6.3)0.60%—IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+528/7/202117/6/2026
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle Management+319/7/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle OptimizationIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next Generation+219/7/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.