Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

5029 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.94%—IBM Datastage ON Cloud PAK FOR Data23/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Pendiente de análisisBaja (2.7)0.19%—IBM Guardium Data ProtectionAI23/9/202623/9/2026
IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AplazadaMedia (6.8)0.29%—JSM Show Post MetadataAI23/9/202623/9/2026
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a…
AplazadaAlta (7.5)0.45%—Fasterxml Jackson-databindAI23/9/202624/9/2026
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in…
AplazadaAlta (7.5)0.45%—Fasterxml Jackson-databindAI23/9/202624/9/2026
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the…
AnalizadaAlta (8.8)0.58%—IBM Datastage ON Cloud PAK FOR Data22/9/202625/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.55%—IBM Datastage ON Cloud PAK FOR Data22/9/202625/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.96%—IBM Datastage ON Cloud PAK FOR Data22/9/202625/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)1.7%—IBM Datastage ON Cloud PAK FOR Data22/9/202625/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.
AnalizadaCrítica (9.9)0.45%—IBM Datastage ON Cloud PAK FOR Data22/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Pendiente de análisisAlta (7)0.14%—NetdataAI22/9/202623/9/2026
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible…
Pendiente de análisisAlta (8.4)0.32%—NetdataAIFail2banAI22/9/202623/9/2026
Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX…
Pendiente de análisisMedia (6.5)0.36%—NetdataAI22/9/202628/9/2026
Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to bypass operator-configured allow dashboard…
Pendiente de análisisMedia (6.5)0.37%—NetdataAI22/9/202625/9/2026
Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h without an upper bound. prd_array_create in src/database/rrdset-pluginsd-array.h can…
Pendiente de análisisMedia (6.5)0.55%—NetdataAI22/9/202623/9/2026
Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. The accepted slot drives reallocz to request an approximately 16 GiB chart-pointer…
Pendiente de análisisAlta (7.5)0.74%—NetdataAI22/9/202623/9/2026
Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output toward WS_MAX_DECOMPRESSED_SIZE without…
Pendiente de análisisAlta (7.8)0.16%—NetdataAI22/9/202623/9/2026
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in…
AplazadaCrítica (9.1)0.51%—DatabasementAI22/9/202623/9/2026
Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user…
AplazadaMedia (5.7)0.23%—Ondata Ckan MCP ServerAI21/9/202624/9/2026
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal…
Pendiente de análisisCrítica (9.2)0.72%—Treasuredata Fluent BITAI21/9/202624/9/2026
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or…
AplazadaMedia (4.3)0.60%—Datalogics Ecommerce DeliveryAI19/9/202621/9/2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.1)0.47%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
AnalizadaAlta (7.6)0.55%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
AnalizadaAlta (8.1)0.63%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
AnalizadaAlta (8.9)0.52%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.