Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (10)0.57%—IBM MQ ApplianceAI18/9/202621/9/2026
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
AnalizadaMedia (5.9)0.18%—IBM MQ Appliance3/3/202617/6/2026
IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1
AnalizadaAlta (7.5)0.35%—IBM MQ Appliance11/7/202517/6/2026
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
AnalizadaMedia (6.5)0.44%—IBM MQ Appliance28/2/202517/6/2026
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
AnalizadaAlta (8.8)0.68%—IBM MQ Appliance28/2/202517/6/2026
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
AnalizadaMedia (4.7)0.13%—IBM MQ Appliance28/2/202517/6/2026
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
AnalizadaMedia (5.3)0.34%—IBM MQ Appliance19/12/202417/6/2026
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.
AnalizadaMedia (6.5)0.70%—IBM MQ ApplianceIBM MQ FOR HPE Nonstop18/12/202417/6/2026
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.
AnalizadaAlta (7.5)0.90%—IBM MQ Appliance27/4/202417/6/2026
IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.
AnalizadaAlta (7.5)0.85%—IBM MQIBM MQ Appliance3/3/202417/6/2026
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
ModificadaAlta (7.5)1.3%—IBM MQ Appliance18/12/202317/6/2026
IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.
ModificadaAlta (7.8)0.18%—IBM MQ Appliance3/11/202317/6/2026
IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.
ModificadaAlta (7.5)0.97%—IBM MQIBM MQ Appliance19/7/202317/6/2026
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
ModificadaAlta (7.5)0.95%—IBM MQ Appliance5/5/202317/6/2026
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.
ModificadaMedia (5.5)0.21%—IBM MQ Appliance5/5/202317/6/2026
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
ModificadaMedia (6.5)0.71%—IBM MQ Appliance5/5/202317/6/2026
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. IBM X-Force ID: 241354.
ModificadaAlta (7.5)0.78%—IBM MQ Appliance10/3/202317/6/2026
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832.
ModificadaMedia (6.5)0.45%—IBM MQ Appliance3/11/202217/6/2026
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
ModificadaBaja (3.3)0.20%—IBM Datapower GatewayIBM MQ Appliance M2002 FirmwareIBM MQ Appliance M2001 Firmware1/8/202217/6/2026
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
ModificadaMedia (6.5)0.88%—IBM MQ Appliance5/4/202217/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.
ModificadaMedia (5.3)1.1%—IBM MQ Appliance5/4/202217/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.
ModificadaMedia (6.5)0.98%—IBM MQ Appliance23/3/202217/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to incorrectly configured authorization checks. IBM X-Force ID: 218276.
ModificadaMedia (5.5)0.67%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.
ModificadaMedia (5.5)0.23%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
ModificadaMedia (6.7)0.26%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.
Orbitaley — Vulnerabilidades