Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.2) | 0.25% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input. | |
| En análisis | Media (6.5) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials. | |
| En análisis | Alta (7.6) | 0.19% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input. | |
| En análisis | Media (6.5) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization. | |
| En análisis | Alta (8.5) | 0.42% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | |
| En análisis | Alta (8.2) | 0.41% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization. | |
| En análisis | Alta (7.9) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery. | |
| En análisis | Alta (8.8) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere. | |
| En análisis | Alta (8.5) | 0.29% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references. | |
| En análisis | Crítica (9.1) | 0.38% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management. | |
| En análisis | Alta (8.8) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials. | |
| En análisis | Alta (8.8) | 0.10% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials. | |
| En análisis | Alta (8.8) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data. | |
| En análisis | Alta (8.8) | 0.50% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity. | |
| En análisis | Crítica (9.1) | 0.35% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints. | |
| En análisis | Media (5.3) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by… | |
| En análisis | Alta (7.3) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization. | |
| Pendiente de análisis | Alta (8.1) | 0.16% | — | Redhat Pki-coreAI | 21/9/2026 | 30/9/2026 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's… | |
| Pendiente de análisis | Alta (7.4) | 0.31% | — | Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI | 21/9/2026 | 24/9/2026 | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to… | |
| Pendiente de análisis | Alta (8.8) | 0.65% | — | Redhat Openshift Container PlatformAIKubernetes Cri-oAI | 21/9/2026 | 1/10/2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the… | |
| Pendiente de análisis | Media (6.1) | 0.42% | — | Redhat QuarkusAIQuarkus QuteAI | 18/9/2026 | 18/9/2026 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to… | |
| Pendiente de análisis | Media (4.2) | 0.28% | — | Redhat EAPAIRedhat ElytronAI | 18/9/2026 | 25/9/2026 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding. | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Redhat ResteasyAI | 18/9/2026 | 18/9/2026 | A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation,… | |
| Pendiente de análisis | Alta (7.4) | 0.23% | — | Redhat ResteasyAI | 18/9/2026 | 5/10/2026 | A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed… | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Redhat Leapp-repositoryAI | 15/9/2026 | 16/9/2026 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that… |