Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

9513 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.45%—IBM DB210/9/202614/9/2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds…
AnalizadaMedia (4.3)0.34%—IBM DB210/9/202614/9/2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
AnalizadaCrítica (9.6)0.54%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
AnalizadaMedia (6.5)0.61%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.79%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.64%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaMedia (6.5)0.77%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
AnalizadaMedia (6.5)0.77%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
AnalizadaAlta (8.1)0.64%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.5)0.55%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
AnalizadaAlta (7.7)0.34%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection…
AnalizadaAlta (8.5)0.29%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift…
AnalizadaAlta (8.5)0.38%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
AnalizadaMedia (5)0.31%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
AnalizadaCrítica (9.1)0.51%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
AnalizadaAlta (7.1)0.20%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
AnalizadaMedia (6.5)0.38%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
AnalizadaCrítica (9.8)0.58%—IBM Contextforge10/9/202616/9/2026
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
En análisisAlta (8.8)0.15%—IBM Aspera Enterprise WebappsAI10/9/202611/9/2026
IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
AnalizadaAlta (8.8)0.50%—IBM APP Connect Enterprise10/9/202616/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
Pendiente de análisisAlta (7.8)0.19%—IBM Webmethods Integration ServerAI10/9/202611/9/2026
IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Pendiente de análisisCrítica (9.1)0.38%—IBM Common Licensing AgentAIIBM ARTAI10/9/202611/9/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.