Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

9513 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.36%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
AnalizadaAlta (7.5)0.40%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
AnalizadaCrítica (9.1)0.34%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
AnalizadaCrítica (9.1)0.38%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
AnalizadaMedia (4.3)0.22%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
AnalizadaMedia (5.4)0.25%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
AnalizadaAlta (7.8)0.13%—IBM I4/9/202610/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaMedia (4.9)0.13%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20268/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
AnalizadaMedia (5.3)0.36%—IBM DB2 Mirror FOR I4/9/202610/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
AnalizadaMedia (5.7)0.22%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
Pendiente de análisisMedia (5.3)0.23%—IBM Cloud PAK FOR Data SystemAI4/9/20268/9/2026
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Pendiente de análisisAlta (7.5)0.25%—IBM Verify Identity Access Advanced Access ControlAI4/9/20268/9/2026
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
Pendiente de análisisMedia (6.5)0.38%—IBM Urbancode DeployAIIBM Devops DeployAI4/9/202610/9/2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property…
AnalizadaAlta (7.5)0.55%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
AnalizadaCrítica (9.6)0.37%—IBM Contextforge4/9/202615/9/2026
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
Pendiente de análisisMedia (6.7)0.12%—IBM QradarAI4/9/20268/9/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
Pendiente de análisisMedia (6.5)0.29%—IBM MQ AgentAI4/9/202610/9/2026
IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests…
Pendiente de análisisAlta (7.7)0.31%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/202610/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an…
Pendiente de análisisCrítica (9.6)0.21%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/20268/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace…
AnalizadaAlta (7.7)0.34%—IBM Contextforge4/9/202615/9/2026
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
AnalizadaMedia (6.5)0.28%—IBM I4/9/20268/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
AnalizadaMedia (5.5)0.10%—IBM I4/9/20268/9/2026
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Pendiente de análisisCrítica (9.8)0.43%—IBM Operational Decision ManagerAI4/9/202610/9/2026
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.