Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.38%—IBM Maximo Application Suite5/8/202610/8/2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
AnalizadaMedia (4.3)0.19%—IBM Maximo Application Suite5/8/202610/8/2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the…
AnalizadaAlta (8.8)0.49%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
AnalizadaMedia (5.3)0.40%—IBM Business Automation Insights5/8/202610/8/2026
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
AnalizadaBaja (3.8)0.17%—IBM Business Automation Workflow5/8/202610/8/2026
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing…
AnalizadaCrítica (9.8)0.65%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use…
AnalizadaAlta (8.5)0.58%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
AnalizadaMedia (4.3)0.30%—IBM Devops DeployIBM Urbancode Deploy30/7/202610/8/2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access…
AnalizadaCrítica (9.8)0.76%—IBM Hardware Management Console30/7/202610/8/2026
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (7.5)0.55%—IBM Datapower Gateway30/7/202610/8/2026
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
AnalizadaCrítica (9.8)0.85%—IBM Webmethods Integration30/7/202610/8/2026
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
AnalizadaMedia (5.3)0.40%—IBM Verify Identity AccessIBM Verify Identity Access Container30/7/202612/8/2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error…
AnalizadaMedia (5.5)0.14%—IBM DB230/7/20265/8/2026
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
AnalizadaAlta (7.5)0.38%—IBM Planning Analytics Local30/7/202612/8/2026
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.
AnalizadaAlta (7.8)0.16%—IBM DB230/7/20265/8/2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Pendiente de análisisMedia (5.5)0.42%—IBM Datapower GatewayAI30/7/202629/9/2026
IBM DataPower Gateway es vulnerable a un ataque de inyección de entidad externa XML (XXE) al procesar datos XML. Un usuario privilegiado podría explotar esta vulnerabilidad para exponer información sensible o consumir recursos de memoria.
AnalizadaMedia (6.1)0.27%—IBM Engineering Requirements Management Doors WEB Access30/7/202629/9/2026
IBM Engineering Requirements Management DOORS y DOORS Web Access 9.7.2.1 hasta 9.7.2.11, y 9.6.1.1 hasta 9.6.1.13 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un atacante no autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista…
AnalizadaMedia (6.3)0.26%—IBM Operations Analytics - LOG Analysis30/7/20261/10/2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, y 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 no invalida la sesión después de un cambio de contraseña, lo que podría permitir a un usuario autenticado suplantar a otro usuario en el sistema.
AnalizadaAlta (7.5)0.46%—IBM Engineering Requirements Management Doors WEB Access30/7/20261/10/2026
IBM Engineering Requirements Management DOORS y DOORS Web Access 9.7.2.1 hasta 9.7.2.11, y 9.6.1.1 hasta 9.6.1.13 no limitan la longitud de una conexión, lo que podría permitir que se produzca un ataque de denegación de servicio HTTP Slowloris. Esto puede hacer que el servidor web deje de responder.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server30/7/202612/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
AnalizadaAlta (8.4)0.15%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2630/7/202626/8/2026
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
Pendiente de análisisAlta (7.5)0.55%—IBM Enterprise Build OF QuarkusAIQuarkus RestAI30/7/202630/7/2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
AnalizadaCrítica (9.8)0.73%—IBM APP Connect Enterprise30/7/20265/8/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
AnalizadaAlta (8.8)0.43%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.