Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
9513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.07% | — | IBM DB2 Mirror FOR I | 4/9/2026 | 8/9/2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory. | |
| Pendiente de análisis | Media (6.2) | 0.11% | — | IBM Enterprise RecordsAIIBM Cp4baAI | 4/9/2026 | 8/9/2026 | CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm. | |
| Analizada | Alta (7.7) | 0.38% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 8/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack. | |
| Analizada | Media (6.5) | 0.32% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket… | |
| Analizada | Media (5.9) | 0.18% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.29% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.39% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and… | |
| Pendiente de análisis | Media (6.2) | 0.11% | — | IBM QiskitAI | 3/9/2026 | 8/9/2026 | Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. | |
| Analizada | Media (5.7) | 0.18% | — | Mongodb Libmongocrypt | 3/9/2026 | 17/9/2026 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption. | |
| Analizada | Alta (7.1) | 0.26% | — | Mongodb Libmongocrypt | 3/9/2026 | 17/9/2026 | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the… | |
| En análisis | Media (6.7) | 0.11% | — | IBM UefiAI | 3/9/2026 | 3/9/2026 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | IBM Cloud PAK FOR Data SystemAI | 28/8/2026 | 31/8/2026 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources. | |
| Analizada | Crítica (9.1) | 0.51% | — | IBM Concert | 28/8/2026 | 2/9/2026 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Pendiente de análisis | Crítica (9.9) | 0.29% | — | IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI | 28/8/2026 | 31/8/2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Administration Runtime Expert FOR IAI | 28/8/2026 | 1/9/2026 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | |
| Analizada | Alta (7.8) | 0.10% | — | IBM AIXIBM Vios | 28/8/2026 | 2/9/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. | |
| Analizada | Media (5.9) | 0.17% | — | IBM Concert | 28/8/2026 | 2/9/2026 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | |
| Analizada | Media (5.9) | 0.16% | — | IBM Integrated Analytics System | 28/8/2026 | 2/9/2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.9) | 0.16% | — | IBM Integrated Analytics System | 28/8/2026 | 2/9/2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Baja (2) | 0.10% | — | Mongodb Libmongocrypt | 27/8/2026 | 17/9/2026 | A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by… | |
| Analizada | Alta (7.8) | 0.11% | — | IBM ViosIBM AIX | 20/8/2026 | 26/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation. | |
| Analizada | Alta (8.8) | 0.14% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. | |
| Analizada | Alta (7.5) | 0.25% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service. | |
| Analizada | Alta (7.5) | 1.0% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart. |