Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
9513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.45% | — | IBM DB2 | 10/9/2026 | 14/9/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds… | |
| Analizada | Media (4.3) | 0.34% | — | IBM DB2 | 10/9/2026 | 14/9/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. | |
| Analizada | Crítica (9.6) | 0.54% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | |
| Analizada | Media (6.5) | 0.61% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.79% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Alta (8.1) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.5) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | |
| Analizada | Alta (7.7) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection… | |
| Analizada | Alta (8.5) | 0.29% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift… | |
| Analizada | Alta (8.5) | 0.38% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. | |
| Analizada | Media (5) | 0.31% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. | |
| Analizada | Crítica (9.1) | 0.51% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. | |
| Analizada | Alta (7.1) | 0.20% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery. | |
| Analizada | Media (6.5) | 0.38% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization. | |
| Analizada | Crítica (9.8) | 0.58% | — | IBM Contextforge | 10/9/2026 | 16/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. | |
| En análisis | Alta (8.8) | 0.15% | — | IBM Aspera Enterprise WebappsAI | 10/9/2026 | 11/9/2026 | IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM APP Connect Enterprise | 10/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization. | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | IBM Webmethods Integration ServerAI | 10/9/2026 | 11/9/2026 | IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | IBM Common Licensing AgentAIIBM ARTAI | 10/9/2026 | 11/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header. |