Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

6126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.2)0.25%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.
En análisisMedia (6.5)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.
En análisisAlta (7.6)0.19%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
En análisisMedia (6.5)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.
En análisisAlta (8.5)0.42%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
En análisisAlta (8.2)0.41%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
En análisisAlta (7.9)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
En análisisAlta (8.8)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.
En análisisAlta (8.5)0.29%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
En análisisCrítica (9.1)0.38%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
En análisisAlta (8.8)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
En análisisAlta (8.8)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
En análisisAlta (8.8)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
En análisisAlta (8.8)0.50%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
En análisisCrítica (9.1)0.35%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
En análisisMedia (5.3)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by…
En análisisAlta (7.3)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Pendiente de análisisAlta (8.1)0.16%—Redhat Pki-coreAI21/9/202630/9/2026
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's…
Pendiente de análisisAlta (7.4)0.31%—Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI21/9/202624/9/2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to…
Pendiente de análisisAlta (8.8)0.65%—Redhat Openshift Container PlatformAIKubernetes Cri-oAI21/9/20261/10/2026
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the…
Pendiente de análisisMedia (6.1)0.42%—Redhat QuarkusAIQuarkus QuteAI18/9/202618/9/2026
A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to…
Pendiente de análisisMedia (4.2)0.28%—Redhat EAPAIRedhat ElytronAI18/9/202625/9/2026
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
Pendiente de análisisAlta (7.5)0.79%—Redhat ResteasyAI18/9/202618/9/2026
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation,…
Pendiente de análisisAlta (7.4)0.23%—Redhat ResteasyAI18/9/20265/10/2026
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed…
Pendiente de análisisAlta (7.3)0.13%—Redhat Leapp-repositoryAI15/9/202616/9/2026
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that…