Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3798 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Aplazada | Alta (8.4) | 0.18% | — | Rakuten Kobo Desktop ApplicationAI | 14/9/2026 | 16/9/2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |
| Analizada | Media (5.3) | 0.43% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |
| Analizada | Alta (8.1) | 0.37% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |
| Analizada | Alta (7.1) | 0.16% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Lenovo Health Android ApplicationAI | 10/9/2026 | 11/9/2026 | A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. | |
| Aplazada | Alta (8.4) | 0.87% | — | Tianxi AI Agent PC ApplicationAI | 10/9/2026 | 11/9/2026 | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. | |
| Analizada | Media (5.3) | 0.49% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service. | |
| Analizada | Alta (7.5) | 0.77% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer | 8/9/2026 | 1/10/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer | 8/9/2026 | 1/10/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | |
| Pendiente de análisis | Alta (7.7) | 0.43% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Pendiente de análisis | Crítica (9.9) | 0.29% | — | IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI | 28/8/2026 | 31/8/2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining… | |
| Pendiente de análisis | Media (4.3) | 0.38% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM… | |
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of… | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is… | |
| Pendiente de análisis | Alta (7.5) | 1.7% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configured staticRoots. A path containing traversal segments can escape the… | |
| Pendiente de análisis | Media (6.5) | 1.3% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java and… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java. Any authenticated account can call GET /api/roles, GET /api/roles/{name}, and… | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event… |