Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

5029 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.36%—3DS Geovia Geospatial Data ManagerAI29/9/202630/9/2026
A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.
AplazadaAlta (8.4)0.29%—Getgrav Grav Plugin DatamanagerAI26/9/202630/9/2026
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by…
Pendiente de análisisCrítica (10)0.95%—Wikimedia External DataAI25/9/202628/9/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.
AplazadaMedia (5.1)0.26%—Open-metadata OpenmetadataAI25/9/202625/9/2026
OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the…
Pendiente de análisisAlta (7.5)0.33%—IBM Guardium Data ProtectionAI25/9/202626/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
Pendiente de análisisAlta (7.2)0.37%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Pendiente de análisisAlta (8.8)2.4%—IBM Guardium Data ProtectionAI25/9/202627/9/2026
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated…
Pendiente de análisisAlta (7.5)0.54%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Pendiente de análisisAlta (7.6)0.18%—IBM Guardium Data ProtectionAI25/9/202625/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
Pendiente de análisisAlta (7.5)0.24%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
AnalizadaAlta (7.1)0.28%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
AnalizadaAlta (8.8)0.41%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
AnalizadaAlta (8.8)0.75%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.
AnalizadaAlta (7.7)0.26%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
AnalizadaAlta (8.8)0.75%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.92%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
AnalizadaAlta (8.8)0.85%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.44%—IBM Datastage ON Cloud PAK FOR Data24/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AplazadaMedia (5.5)0.25%—Softnews Media Group Datalife EngineAI23/9/202624/9/2026
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available…
AnalizadaAlta (8.8)0.98%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
AnalizadaAlta (7.7)0.28%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
AnalizadaAlta (7.7)0.23%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.
AnalizadaMedia (6.5)0.33%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
AnalizadaAlta (8.8)0.94%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.54%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.