Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.0%—IBM APP Connect Enterprise30/7/20265/8/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
AnalizadaAlta (7.5)0.62%—IBM APP Connect Enterprise30/7/20265/8/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
AnalizadaAlta (7.5)0.40%—IBM APP Connect Enterprise30/7/20265/8/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
AnalizadaAlta (7.3)0.17%—IBM Aspera30/7/202613/8/2026
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
AnalizadaMedia (5.4)0.23%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.
AnalizadaMedia (5.4)0.23%—IBM Sterling B2B IntegratorIBM Sterling File Gateway30/7/202629/9/2026
IBM Sterling B2B Integrator 6.2.2.0 hasta 6.2.2.0_1 y IBM Sterling File Gateway 6.2.2.0 hasta 6.2.2.0_1 son vulnerables a cross-site scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y lo que…
AnalizadaMedia (5.4)0.23%—IBM Sterling B2B IntegratorIBM Sterling File Gateway30/7/202629/9/2026
IBM Sterling B2B Integrator 6.1.2.0 hasta 6.1.2.7_2, 6.2.0.0 hasta 6.2.0.5_2, 6.2.1.0 hasta 6.2.1.1_2, y 6.2.2.0 hasta 6.2.2.0_1 y IBM Sterling File Gateway 6.1.2.0 hasta 6.1.2.7_2, 6.2.0.0 hasta 6.2.0.5_2, 6.2.1.0 hasta 6.2.1.1_2, y 6.2.2.0 hasta 6.2.2.0_1 el componente de servidor Ebics es vulnerable a cross-site…
AnalizadaAlta (8.8)0.15%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
ModificadaAlta (8.7)0.34%—IBM Websphere Application Server28/7/20266/8/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
AnalizadaAlta (7.5)0.50%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
AnalizadaAlta (7.5)0.46%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
AnalizadaAlta (8.2)0.34%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
AnalizadaCrítica (9.8)0.61%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
AnalizadaCrítica (9.8)0.68%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
AnalizadaCrítica (9.3)0.45%—IBM Aspera28/7/202613/8/2026
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
AnalizadaAlta (7.2)1.6%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
AnalizadaAlta (7.2)0.82%—IBM Aspera Faspex28/7/20265/8/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Pendiente de análisisAlta (7.3)0.33%—IBM Observability With Instana AgentAIInstana CoreAI28/7/202630/7/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
AnalizadaAlta (7.5)0.45%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
AnalizadaMedia (6.1)0.30%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
AnalizadaCrítica (9.8)0.97%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.