Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
9513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.37% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to improper authentication. | |
| Analizada | Media (6.5) | 0.34% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | |
| Analizada | Media (5.5) | 0.13% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption. | |
| Analizada | Media (6.7) | 0.17% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buffer overflow. | |
| Analizada | Alta (7.8) | 0.17% | — | IBM ViosIBM AIX | 20/8/2026 | 26/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| Analizada | Alta (8.8) | 0.17% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. | |
| Analizada | Alta (7) | 0.07% | — | IBM ViosIBM AIX | 20/8/2026 | 26/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | |
| Analizada | Alta (8.8) | 0.15% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow. | |
| Analizada | Alta (8.8) | 0.19% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow. | |
| Analizada | Alta (7) | 0.07% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | |
| Analizada | Crítica (9.1) | 0.56% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input. | |
| Analizada | Alta (7.8) | 0.09% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation. | |
| Analizada | Alta (7.8) | 0.08% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| Analizada | Alta (7) | 0.10% | — | IBM ViosIBM AIX | 20/8/2026 | 24/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition. | |
| Analizada | Media (6) | 0.13% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+20 | 19/8/2026 | 25/8/2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested. | |
| Analizada | Media (6.2) | 0.10% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+22 | 19/8/2026 | 25/8/2026 | IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to… | |
| Analizada | Media (6.8) | 0.37% | — | IBM OpenbmcIBM Power System E1050 (9043-mrx) FirmwareIBM Power System L1022 (9786-22h) FirmwareIBM Power System L1024 (9786-42h) Firmware+5 | 19/8/2026 | 2/9/2026 | IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact. | |
| Analizada | Alta (8.1) | 0.43% | — | IBM Portieris | 19/8/2026 | 2/9/2026 | IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. |