Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

9598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.62%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.1)0.39%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
ModificadaAlta (8.8)0.41%—IBM I22/6/20269/7/2026
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
AnalizadaCrítica (9.1)0.59%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof…
AnalizadaAlta (7.5)0.20%—IBM DatacapIBM Datacap Navigator22/6/202626/6/2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
AnalizadaMedia (6.1)0.24%—IBM DatacapIBM Datacap Navigator22/6/202626/6/2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
ModificadaAlta (8.8)0.37%—IBM Watson Speech Services Cartridge22/6/202623/7/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
En análisisCrítica (9.1)0.63%—IBM Storage Protect22/6/202626/6/2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential…
AnalizadaMedia (5.4)0.23%—IBM Tririga Application Platform22/6/202630/6/2026
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.3)0.47%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
AnalizadaMedia (6.1)0.25%—IBM Engineering Workflow Management22/6/20261/10/2026
IBM Engineering Workflow Management 7.0.2 hasta 7.0.2 Interim Fix 035, 7.0.3 hasta 7.0.3 Interim Fix 017, y 7.1 hasta 7.1 Interim Fix 004 es vulnerable a la inyección de encabezados HTTP, causada por una validación incorrecta de la entrada por parte de los encabezados HOST. Esto podría permitir a un atacante realizar…
AnalizadaMedia (5.3)0.25%—IBM DB2IBM DB2 Warehouse22/6/202626/9/2026
IBM Db2 on Cloud Pak for Data y Db2 Warehouse on Cloud Pak for Data versiones 4.8, 5.0, 5.1, 5.2 y 5.3 podrían permitir a un usuario autenticado eludir la validación del lado del cliente y manipular los datos de entrada utilizando técnicas de hombre en el medio.
AnalizadaMedia (5.4)0.23%—IBM Engineering Workflow Management22/6/20266/10/2026
IBM Engineering Workflow Management 7.0.3 hasta 7.0.3 Interim Fix 020, y 7.1 hasta 7.1 Interim Fix 007 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría…
AnalizadaMedia (6.5)0.34%—IBM DB2IBM DB2 Warehouse22/6/20266/10/2026
Las versiones 4.8, 5.0, 5.1, 5.2, 5.3 de IBM Db2 en Cloud Pak for Data y Db2 Warehouse en Cloud Pak for Data podrían permitir a un usuario privilegiado realizar operaciones y obtener información sensible fuera de su autoridad debido a una validación de token indebida.
AnalizadaMedia (6.5)0.42%—IBM DB2IBM DB2 Warehouse22/6/20261/10/2026
IBM Db2 on Cloud Pak for Data y Db2 Warehouse on Cloud Pak for Data versiones 4.8, 5.0, 5.1, 5.2, 5.3 podrían permitir a un usuario autenticado causar una denegación de servicio al crear nuevas bases de datos debido a una asignación incorrecta de recursos.
AnalizadaAlta (7.5)0.46%—IBM Qiskit Software Development KIT12/6/202617/6/2026
IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser.
AnalizadaAlta (8.8)0.49%—IBM I11/6/202617/6/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
AnalizadaMedia (4.4)0.09%—IBM Security Qradar EDR11/6/20261/10/2026
IBM Security QRadar EDR 3.12 hasta 3.12.24 almacena credenciales de usuario en texto plano que pueden ser leídas por un usuario privilegiado local.
AnalizadaAlta (8.5)0.68%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0 y 8.5 se ve afectado por una validación incorrecta de datos proporcionados por el usuario durante la deserialización al usar el componente SAML Web Single Sign-On. Esto podría resultar en ejecución remota de código a través de una solicitud HTTP manipulada cuando se combina con una…
AnalizadaCrítica (9)0.62%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0 y 8.5 es vulnerable a una posible ejecución remota de código debido a la deserialización de datos no confiables a través de puntos finales JAX-WS con WS-Security.
AnalizadaCrítica (9)0.64%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Servidor de Aplicaciones 9.0 y 8.5 es vulnerable a la ejecución remota de código causada por la elusión de controles de seguridad.
AnalizadaCrítica (9.1)0.47%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Servidor de Aplicaciones 9.0 y 8.5 es vulnerable a la suplantación de identidad.
AnalizadaAlta (8.8)0.81%—IBM I Access Client Solutions1/6/202626/8/2026
IBM i Access Family 1.1.5.0 hasta 1.1.9.12 IBM i Access Client Solutions (ACS) es vulnerable a ejecución remota de código cuando se configura para escuchar solicitudes de IBM i Navigator.
AnalizadaMedia (4.3)0.22%—IBM Business Automation Workflow27/5/202617/6/2026
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
AnalizadaMedia (6.5)0.45%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage…