Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | — | — | LibmikmodAI | 6/10/2026 | 6/10/2026 | libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized patterns. Attackers can supply a crafted IT module with more than 200 pattern rows, causing IT_ConvertTrack() to read past the itpat buffer… | |
| Aplazada | Alta (8.5) | — | — | LibmikmodAI | 6/10/2026 | 6/10/2026 | libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential… | |
| Analizada | Alta (8.1) | 0.39% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | |
| Analizada | Alta (8.8) | 0.74% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. | |
| Analizada | Crítica (9.1) | 0.68% | — | IBM Guardium Data Protection | 29/9/2026 | 2/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. | |
| Analizada | Alta (7.2) | 0.68% | — | IBM Guardium Data Protection | 29/9/2026 | 2/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.57% | — | IBM Datastage ON Cloud PAK FOR Data | 29/9/2026 | 2/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| Analizada | Alta (7.8) | 0.09% | — | IBM I | 29/9/2026 | 2/10/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path. | |
| Analizada | Alta (7.1) | 0.18% | — | IBM Power System E1080 (9080-hex) FirmwareIBM Power System E1180 (9080-heu) FirmwareIBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) Firmware+5 | 25/9/2026 | 30/9/2026 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to… | |
| En análisis | Alta (7.5) | 0.33% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 26/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system. | |
| En análisis | Alta (7.2) | 0.37% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system. | |
| En análisis | Alta (8.8) | 2.4% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 27/9/2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated… | |
| En análisis | Alta (7.5) | 0.54% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| En análisis | Alta (7.6) | 0.18% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 25/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database. | |
| En análisis | Alta (7.5) | 0.24% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token. | |
| Analizada | Alta (7.1) | 0.28% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.8) | 0.41% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | |
| Analizada | Alta (8.8) | 0.75% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | |
| Analizada | Alta (7.7) | 0.26% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| Analizada | Alta (8.8) | 0.75% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.92% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | |
| Analizada | Alta (8.8) | 0.85% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Datastage ON Cloud PAK FOR Data | 24/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Pendiente de análisis | Alta (8.6) | 0.43% | — | IBM Enterprise Build OF QuarkusAI | 24/9/2026 | 24/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Media (4.9) | 0.32% | — | IBM Contextforge | 24/9/2026 | 29/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files… |