Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
9598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.59% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM I | 13/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| En análisis | Alta (8.2) | 0.56% | — | IBM I | 13/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. | |
| En análisis | Crítica (9.8) | 0.50% | — | IBM I | 13/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. | |
| Analizada | Alta (8.2) | 0.51% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. | |
| Analizada | Crítica (9.8) | 0.38% | — | IBM DB2 | 12/8/2026 | 17/8/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. | |
| Analizada | Media (5.5) | 0.15% | — | IBM DB2 | 12/8/2026 | 17/8/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. | |
| Analizada | Baja (3.3) | 0.13% | — | IBM DB2 | 12/8/2026 | 17/8/2026 | IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Alta (7.8) | 0.21% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.1) | 0.34% | — | IBM DB2 | 12/8/2026 | 18/8/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. | |
| Analizada | Alta (7.1) | 0.11% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. | |
| Analizada | Alta (7.3) | 0.43% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | |
| Analizada | Crítica (9.6) | 0.17% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 18/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. | |
| Analizada | Crítica (9.8) | 0.39% | — | IBM DB2 | 12/8/2026 | 18/8/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. | |
| Analizada | Media (5.3) | 0.28% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. | |
| Analizada | Media (4.3) | 0.34% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs. | |
| Analizada | Media (5.4) | 0.33% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | |
| Analizada | Alta (8.8) | 0.79% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (6.5) | 0.41% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name. | |
| Analizada | Alta (8.8) | 0.79% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters. |