Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.30% | — | GratisfactionAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Booking ActivitiesAI | 30/9/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Aplazada | Alta (7.6) | 0.31% | — | WP Activity LOGAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Qodeinteractive QI Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Apache Activemq ArtemisAI | 28/9/2026 | 29/9/2026 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated… | |
| Analizada | Media (6.2) | 0.13% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | |
| Analizada | Alta (8.2) | 0.30% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. | |
| Analizada | Media (4.4) | 0.09% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. | |
| Analizada | Alta (7.3) | 0.22% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool… | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator… | |
| Analizada | Media (5.4) | 0.15% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential… | |
| Analizada | Alta (8.8) | 0.25% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to… | |
| Analizada | Alta (7.3) | 0.26% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function. | |
| Analizada | Alta (7.4) | 0.22% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |
| Analizada | Alta (8.1) | 0.25% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. | |
| Analizada | Alta (7.1) | 0.18% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | |
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Analizada | Alta (7.4) | 0.13% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | |
| Analizada | Baja (3.7) | 0.24% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. | |
| Analizada | Alta (7.4) | 0.20% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. | |
| Analizada | Crítica (9.9) | 0.54% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |