Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.19% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input. | |
| Analizada | Alta (7.5) | 0.24% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization. | |
| Analizada | Alta (8.8) | 0.42% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | |
| Analizada | Alta (7.5) | 0.41% | — | IBM Financial Transaction Manager | 22/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization. | |
| En análisis | Alta (7.9) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery. | |
| En análisis | Alta (8.8) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere. | |
| En análisis | Alta (8.5) | 0.29% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references. | |
| En análisis | Crítica (9.1) | 0.38% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management. | |
| En análisis | Alta (8.8) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials. | |
| En análisis | Alta (8.8) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials. | |
| En análisis | Alta (8.8) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data. | |
| En análisis | Alta (8.8) | 0.50% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity. | |
| En análisis | Crítica (9.1) | 0.35% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints. | |
| En análisis | Media (5.3) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by… | |
| En análisis | Alta (7.3) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization. | |
| Pendiente de análisis | Crítica (9.6) | 0.73% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope… | |
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.… | |
| Pendiente de análisis | Crítica (9.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 25/9/2026 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is… | |
| Pendiente de análisis | Alta (8.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 22/9/2026 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the… | |
| Pendiente de análisis | Alta (7.1) | 1.5% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 24/9/2026 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of… | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Crítica (9.3) | 2.2% | ⚠ Explotación activa💥 PoC | F5 Big-ip Access Policy Manager | 22/9/2026 | 23/9/2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. |