Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.47% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |
| Modificada | Alta (8.1) | 0.39% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |
| Modificada | Crítica (9.8) | 0.42% | — | IBM Websphere Application Server | 30/6/2026 | 29/7/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. | |
| Analizada | Alta (7.5) | 0.47% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. | |
| Modificada | Crítica (9.8) | 0.36% | — | IBM Websphere Application Server | 30/6/2026 | 6/8/2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | |
| Analizada | Alta (7.5) | 0.78% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.1) | 0.39% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure. | |
| Analizada | Crítica (9.1) | 0.59% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof… | |
| Analizada | Alta (7.3) | 0.47% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. | |
| Analizada | Alta (8.5) | 0.68% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain. | |
| Analizada | Crítica (9) | 0.62% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | |
| Analizada | Crítica (9) | 0.64% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | |
| Analizada | Crítica (9.1) | 0.47% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | |
| Modificada | Media (5.9) | 0.30% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window. | |
| Analizada | Alta (7.5) | 0.69% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to… | |
| Analizada | Crítica (9.8) | 0.94% | — | IBM Websphere Application Server | 26/5/2026 | 23/7/2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request. | |
| Analizada | Alta (7.5) | 0.37% | — | IBM Websphere Application Server | 26/5/2026 | 23/7/2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request. |