Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

9513 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.43%—IBM Websphere Application Server10/9/202615/9/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
AnalizadaAlta (8.1)0.37%—IBM Websphere Application Server10/9/202615/9/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
AnalizadaAlta (7.1)0.16%—IBM Websphere Application Server10/9/202615/9/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
AnalizadaMedia (5.3)0.49%—IBM Websphere Application Server10/9/202616/9/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.
AnalizadaAlta (7.5)0.77%—IBM Websphere Application Server10/9/202616/9/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
Pendiente de análisisAlta (7.4)0.26%—IBM Enterprise Build OF QuarkusAI8/9/20269/9/2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
AnalizadaAlta (7.4)0.26%—IBM Contextforge4/9/202615/9/2026
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
AnalizadaAlta (8.8)0.33%—IBM Contextforge4/9/202615/9/2026
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
AnalizadaAlta (8.8)0.25%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
AnalizadaCrítica (9.8)0.34%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
AnalizadaAlta (7.5)0.20%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
AnalizadaMedia (6.5)0.29%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
AnalizadaMedia (6.5)0.29%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
AnalizadaMedia (4.4)0.10%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
AnalizadaAlta (7.8)0.12%—IBM I4/9/20269/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaBaja (3.3)0.15%—IBM DB2 Mirror FOR I4/9/202610/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
AnalizadaAlta (7.5)0.39%—IBM I4/9/20269/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
AnalizadaMedia (5.5)0.21%—IBM I4/9/20269/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
AnalizadaMedia (5.5)0.09%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
AnalizadaMedia (5.5)0.10%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
AnalizadaMedia (5.4)0.24%—IBM I4/9/20269/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
AnalizadaMedia (6.5)0.35%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
AnalizadaMedia (5.5)0.21%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.