Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.47% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |
| Modificada | Alta (8.1) | 0.39% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |
| Modificada | Crítica (9.8) | 0.42% | — | IBM Websphere Application Server | 30/6/2026 | 29/7/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow… | |
| Analizada | Crítica (10) | 6.1% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an… | |
| Analizada | Crítica (9.9) | 0.51% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who… | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including… | |
| Analizada | Alta (7.5) | 0.47% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. | |
| Modificada | Crítica (9.8) | 0.36% | — | IBM Websphere Application Server | 30/6/2026 | 6/8/2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | |
| Analizada | Alta (7.5) | 0.78% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.1) | 0.39% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure. | |
| Analizada | Crítica (9.1) | 0.59% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof… | |
| Analizada | Alta (7.3) | 0.47% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. | |
| Analizada | Alta (8.5) | 0.68% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain. | |
| Analizada | Crítica (9) | 0.62% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | |
| Analizada | Crítica (9) | 0.64% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | |
| Analizada | Crítica (9.1) | 0.47% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. |