Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

9541 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.32%—IBM ViosIBM AIX19/8/202620/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.
AnalizadaCrítica (9.9)1.1%—IBM ViosIBM AIX19/8/202620/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaCrítica (9.1)0.63%—IBM ViosIBM AIX19/8/202620/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.
AnalizadaAlta (8.2)0.59%—IBM ViosIBM AIX19/8/202620/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
AnalizadaAlta (7.5)0.46%—IBM ViosIBM AIX19/8/202620/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.
AplazadaMedia (4.8)0.17%—Konstanty Bialkowski LibmodplugAI18/8/20268/9/2026
libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array.…
AnalizadaAlta (7.5)0.85%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
AnalizadaAlta (8.1)0.54%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
AnalizadaMedia (6.5)0.35%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
AnalizadaMedia (5.4)0.36%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
AnalizadaCrítica (9.8)0.50%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
AnalizadaCrítica (9.8)0.80%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
AnalizadaCrítica (9.8)0.73%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
AnalizadaAlta (8.6)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
AnalizadaMedia (6.5)3.1%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
AnalizadaAlta (7.5)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
AnalizadaMedia (6.5)0.52%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
AnalizadaMedia (6.5)0.66%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
AnalizadaAlta (7.5)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
AnalizadaMedia (4.3)0.32%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
AnalizadaAlta (7.5)0.85%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
AnalizadaMedia (6.5)0.46%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
AnalizadaAlta (8.8)0.50%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
AnalizadaAlta (7.5)0.24%—IBM DB2 Mirror FOR I14/8/202626/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
AnalizadaMedia (5.5)0.16%—IBM Storage Scale13/8/202618/8/2026
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM…