Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
9598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.45% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Crítica (9.8) | 0.80% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name. | |
| Analizada | Alta (8.8) | 0.49% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | |
| Analizada | Alta (8.1) | 0.35% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a… | |
| Analizada | Alta (8.7) | 0.49% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by… | |
| Analizada | Baja (3.1) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |
| Analizada | Alta (7.4) | 0.32% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Media (4.2) | 0.16% | — | IBM Datapower Gateway | 12/8/2026 | 4/10/2026 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing,… | |
| Pendiente de análisis | Crítica (10) | 0.57% | — | IBM Doors NextAI | 12/8/2026 | 23/9/2026 | IBM DOORS Next 7.0.3 hasta 7.0.3 Interim Fix 018 podría permitir a un usuario autenticado eludir la lógica de seguridad para realizar actividades no autorizadas. | |
| Analizada | Alta (8.8) | 0.52% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands. | |
| Analizada | Alta (8.8) | 0.75% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority. | |
| Analizada | Media (5) | 0.27% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition. | |
| Analizada | Alta (8.3) | 0.54% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation. | |
| Analizada | Media (6.3) | 0.37% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter. | |
| Analizada | Media (6.5) | 0.42% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (7.8) | 0.30% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Crítica (9.9) | 0.47% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. | |
| Analizada | Media (6.8) | 0.34% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token. | |
| Analizada | Media (6.5) | 0.66% | — | IBM I | 12/8/2026 | 17/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (6.5) | 0.47% | — | IBM I | 12/8/2026 | 13/8/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command. |