Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
5029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.36% | — | 3DS Geovia Geospatial Data ManagerAI | 29/9/2026 | 30/9/2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. | |
| Aplazada | Alta (8.4) | 0.29% | — | Getgrav Grav Plugin DatamanagerAI | 26/9/2026 | 30/9/2026 | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by… | |
| Pendiente de análisis | Crítica (10) | 0.95% | — | Wikimedia External DataAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7. | |
| Aplazada | Media (5.1) | 0.26% | — | Open-metadata OpenmetadataAI | 25/9/2026 | 25/9/2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the… | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 26/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system. | |
| Pendiente de análisis | Alta (7.2) | 0.37% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system. | |
| Pendiente de análisis | Alta (8.8) | 2.4% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 27/9/2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated… | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Pendiente de análisis | Alta (7.6) | 0.18% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 25/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database. | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token. | |
| Analizada | Alta (7.1) | 0.28% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.8) | 0.41% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | |
| Analizada | Alta (8.8) | 0.75% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | |
| Analizada | Alta (7.7) | 0.26% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| Analizada | Alta (8.8) | 0.75% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.92% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | |
| Analizada | Alta (8.8) | 0.85% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Aplazada | Media (5.5) | 0.25% | — | Softnews Media Group Datalife EngineAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available… | |
| Analizada | Alta (8.8) | 0.98% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection. | |
| Analizada | Alta (7.7) | 0.28% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Alta (7.7) | 0.23% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments. | |
| Analizada | Media (6.5) | 0.33% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts. | |
| Analizada | Alta (8.8) | 0.94% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.54% | — | IBM Datastage ON Cloud PAK FOR Data | 23/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation. |