Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
9513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.1) | 0.16% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | |
| Pendiente de análisis | Media (4.8) | 0.22% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | |
| Pendiente de análisis | Media (6.4) | 0.20% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. | |
| Pendiente de análisis | Alta (7.5) | 0.40% | — | IBM DB2AI | 14/9/2026 | 16/9/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.2) | 0.12% | — | IBM Common Licensing AgentAIIBM ARTAI | 14/9/2026 | 16/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values,… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | IBM IAIIBM Navigator FOR IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile… | |
| Pendiente de análisis | Media (4.2) | 0.14% | — | IBM IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process. | |
| Pendiente de análisis | Alta (7.1) | 0.39% | — | IBM MQAI | 14/9/2026 | 18/9/2026 | IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Media (5.4) | 0.15% | — | IBM Verify Identity AccessAI | 14/9/2026 | 19/9/2026 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property. | |
| Analizada | Alta (8.8) | 0.93% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability. | |
| Aplazada | Media (6.6) | 0.35% | — | IBM ContextforgeAI | 14/9/2026 | 30/9/2026 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject… | |
| Aplazada | Media (6.1) | 0.26% | — | IBM Marketing PlatformAI | 11/9/2026 | 22/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |
| Analizada | Alta (8.1) | 0.38% | — | IBM DB2 | 10/9/2026 | 14/9/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. |