Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

9538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.50%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.41%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
AnalizadaCrítica (9.8)0.80%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
AnalizadaCrítica (9.4)0.52%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.
AnalizadaAlta (7)0.10%—IBM AIXIBM Vios19/8/202626/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
AnalizadaAlta (7.5)0.35%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
AnalizadaAlta (7.5)0.55%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
AnalizadaCrítica (9.8)0.62%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
AnalizadaMedia (5.3)0.40%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.
AnalizadaAlta (7.5)0.55%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
AnalizadaMedia (5.3)0.25%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
AnalizadaMedia (5.9)0.44%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
AnalizadaMedia (4.2)0.33%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write.
AnalizadaAlta (7.5)0.55%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to unbounded recursion.
AnalizadaCrítica (9.3)0.25%—IBM AIXIBM Vios19/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
AnalizadaMedia (4.5)0.26%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1319/8/202625/8/2026
IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). An attacker with authenticated administrator-level access can cause the VMI to crash. The VMI will restart…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2219/8/202625/8/2026
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2219/8/202625/8/2026
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to…
AnalizadaMedia (5.4)0.26%—IBM Ds8900f FirmwareIBM Ds8a00 Firmware19/8/202629/9/2026
IBM System Storage DS8A00 10.1.3.0 hasta 10.11.35.0 y IBM DS8900F 89.40.83.0 hasta 89.44.25.0 podrían permitir a un usuario autenticado leer o modificar el historial de comandos de otro usuario debido a un nombre de archivo controlado externamente.
AnalizadaAlta (8.8)0.24%—IBM Ds8900f FirmwareIBM Ds8a00 Firmware19/8/202629/9/2026
IBM System Storage DS8A00 10.1.3.0 hasta 10.11.35.0 y IBM DS8900F 89.40.83.0 hasta 89.44.25.0 podría permitir a un usuario autenticado crear un usuario con roles de usuario privilegiados debido a privilegios definidos incorrectamente con acciones inseguras.
AnalizadaAlta (7.4)0.46%—IBM Ds8900f FirmwareIBM Ds8a00 Firmware19/8/202629/9/2026
IBM System Storage DS8A00 10.1.3.0 hasta 10.11.35.0 y IBM DS8900F 89.40.83.0 hasta 89.44.25.0 podría permitir a un atacante eludir la autenticación de seguridad debido a una codificación indebida de la salida de comandos DSCLI para obtener información sensible o causar una denegación de servicio.
AnalizadaMedia (6.7)0.16%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1519/8/202625/8/2026
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be…
AnalizadaAlta (8.3)0.15%—IBM Power System E1080 (9080-hex) FirmwareIBM Power System E1180 (9080-heu) FirmwareIBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) Firmware+519/8/202625/8/2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform…
AnalizadaMedia (6.8)0.34%—IBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) FirmwareIBM Power System S914 (9009-41g) FirmwareIBM Power System S924 (9009-42g) Firmware+519/8/202625/8/2026
IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code,…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+619/8/202625/8/2026
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over…