Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

813 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.42%—Redhat Hypershift OperatorAI5/10/20266/10/2026
A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability…
AplazadaMedia (6.1)0.21%—Wpsoul GreenshiftAI2/10/20262/10/2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
Pendiente de análisisAlta (7.5)0.50%—Openshift ConsoleAI23/9/20261/10/2026
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests…
Pendiente de análisisAlta (7.2)0.33%—Openshift ConsoleAIOpenshift CatalogdAI23/9/20261/10/2026
A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the…
En análisisMedia (6.2)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
En análisisAlta (8.2)0.30%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
En análisisMedia (4.4)0.09%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
En análisisAlta (7.3)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool…
En análisisCrítica (9.3)0.19%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator…
En análisisMedia (5.4)0.15%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential…
En análisisAlta (8.8)0.25%—IBM Financial Transaction ManagerAIRedhat OpenshiftAIIBM PaydirAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to…
En análisisAlta (7.3)0.26%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
En análisisAlta (7.4)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
En análisisAlta (8.1)0.25%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
En análisisMedia (6.5)0.27%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
En análisisMedia (6.5)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
En análisisAlta (7.1)0.18%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
En análisisAlta (7.4)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
En análisisBaja (3.7)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
En análisisAlta (7.4)0.20%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
En análisisMedia (6.5)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
En análisisAlta (8)0.17%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.
En análisisMedia (5.4)0.14%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
En análisisAlta (7.4)0.12%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
En análisisAlta (8.1)0.30%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.