Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
21.063 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.22% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | |
| Pendiente de análisis | Media (6.4) | 0.20% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple Macos | 14/9/2026 | 18/9/2026 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7. Connecting a malicious accessory may cause unexpected system termination. | |
| Analizada | Media (5.5) | 0.15% | — | Apple Macos | 14/9/2026 | 18/9/2026 | This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts. | |
| Analizada | Media (5.5) | 0.18% | — | Apple Macos | 14/9/2026 | 18/9/2026 | A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files. | |
| Analizada | Media (4.4) | 0.15% | — | Apple Macos | 14/9/2026 | 18/9/2026 | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks. | |
| Analizada | Media (5.5) | 0.18% | — | Apple Macos | 14/9/2026 | 18/9/2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sonoma 14.8.8. An app may be able to access sensitive user data. | |
| Analizada | Alta (7.1) | 0.17% | — | Apple Macos | 14/9/2026 | 18/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure. | |
| Analizada | Media (6.5) | 0.34% | — | Apple Macos | 14/9/2026 | 18/9/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure. | |
| Analizada | Media (5.4) | 0.20% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 14/9/2026 | 18/9/2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting. | |
| Analizada | Media (5.5) | 0.15% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 14/9/2026 | 18/9/2026 | This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data. | |
| Analizada | Baja (3.3) | 0.14% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 14/9/2026 | 18/9/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to read device name. | |
| Analizada | Media (5.5) | 0.15% | — | Apple IpadosApple Iphone OSApple Visionos | 14/9/2026 | 18/9/2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service. | |
| Analizada | Baja (3.5) | 0.23% | — | Apple MacosApple Watchos | 14/9/2026 | 18/9/2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information. | |
| Analizada | Baja (3.3) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 21/9/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier. | |
| Analizada | Baja (3.3) | 0.16% | — | Apple IpadosApple Iphone OSApple Visionos | 14/9/2026 | 21/9/2026 | A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences. | |
| Analizada | Media (5.5) | 0.17% | — | Apple IpadosApple Iphone OSApple Watchos | 14/9/2026 | 18/9/2026 | A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files. | |
| Analizada | Media (5.5) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 14/9/2026 | 18/9/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data. |