Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

936 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.47%—IBM Websphere Application Server28/7/20263/8/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
ModificadaAlta (8.1)0.39%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
ModificadaAlta (8.7)0.34%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
ModificadaAlta (7.5)0.46%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
ModificadaCrítica (9.8)0.42%—IBM Websphere Application Server30/6/202629/7/2026
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
AnalizadaMedia (6.1)0.34%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
AnalizadaMedia (6.5)0.27%—IBM Websphere Extreme Scale30/6/20262/7/2026
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow…
AnalizadaCrítica (10)6.1%—IBM Websphere Extreme Scale30/6/20262/7/2026
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an…
AnalizadaCrítica (9.9)0.51%—IBM Websphere Extreme Scale30/6/20263/7/2026
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who…
AnalizadaAlta (8.8)0.55%—IBM Websphere Extreme Scale30/6/20263/7/2026
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including…
AnalizadaAlta (7.5)0.47%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
ModificadaCrítica (9.8)0.36%—IBM Websphere Application Server30/6/20266/8/2026
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
AnalizadaAlta (7.5)0.78%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
AnalizadaCrítica (9.8)0.40%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaAlta (7.5)0.62%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.1)0.39%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
AnalizadaCrítica (9.1)0.59%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof…
AnalizadaAlta (7.3)0.47%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
AnalizadaAlta (8.5)0.68%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
AnalizadaCrítica (9)0.62%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
AnalizadaCrítica (9)0.64%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
AnalizadaCrítica (9.1)0.47%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Orbitaley — Vulnerabilidades