Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
9513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.43% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |
| Analizada | Alta (8.1) | 0.37% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |
| Analizada | Alta (7.1) | 0.16% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. | |
| Analizada | Media (5.3) | 0.49% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service. | |
| Analizada | Alta (7.5) | 0.77% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space. | |
| Pendiente de análisis | Alta (7.4) | 0.26% | — | IBM Enterprise Build OF QuarkusAI | 8/9/2026 | 9/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input. | |
| Analizada | Alta (7.4) | 0.26% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. | |
| Analizada | Alta (8.8) | 0.33% | — | IBM Contextforge | 4/9/2026 | 15/9/2026 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |
| Analizada | Alta (8.8) | 0.25% | — | IBM I | 4/9/2026 | 8/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM I | 4/9/2026 | 8/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM I | 4/9/2026 | 10/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. | |
| Analizada | Media (6.5) | 0.29% | — | IBM I | 4/9/2026 | 8/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. | |
| Analizada | Media (6.5) | 0.29% | — | IBM I | 4/9/2026 | 10/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. | |
| Analizada | Media (4.4) | 0.10% | — | IBM I | 4/9/2026 | 8/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM I | 4/9/2026 | 9/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Baja (3.3) | 0.15% | — | IBM DB2 Mirror FOR I | 4/9/2026 | 10/9/2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. | |
| Analizada | Alta (7.5) | 0.39% | — | IBM I | 4/9/2026 | 9/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. | |
| Analizada | Media (5.5) | 0.21% | — | IBM I | 4/9/2026 | 9/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |
| Analizada | Media (5.5) | 0.09% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. | |
| Analizada | Media (5.5) | 0.10% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion. | |
| Analizada | Media (5.4) | 0.24% | — | IBM I | 4/9/2026 | 9/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. | |
| Analizada | Media (6.5) | 0.35% | — | IBM I | 4/9/2026 | 10/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. | |
| Analizada | Media (5.5) | 0.21% | — | IBM I | 4/9/2026 | 10/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. |