Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.42% | — | IBM Websphere Application Server | 30/6/2026 | 29/7/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. | |
| Analizada | Alta (7.5) | 0.47% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. | |
| Modificada | Crítica (9.8) | 0.36% | — | IBM Websphere Application Server | 30/6/2026 | 6/8/2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | |
| Analizada | Alta (7.5) | 0.78% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.1) | 0.39% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure. | |
| Analizada | Crítica (9.1) | 0.59% | — | IBM Websphere Application Server | 22/6/2026 | 24/6/2026 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof… | |
| Analizada | Alta (7.3) | 0.47% | — | IBM Websphere Application Server | 22/6/2026 | 23/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | SAP Application Server AbapAI | 9/6/2026 | 23/7/2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of privileges. This has high impact on integrity with low impact on… | |
| Pendiente de análisis | Crítica (9.9) | 0.32% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data… | |
| Pendiente de análisis | Crítica (9) | 0.63% | — | SAP Netweaver Application Server JavaAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive… | |
| Analizada | Alta (8.5) | 0.68% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain. | |
| Analizada | Crítica (9) | 0.62% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | |
| Analizada | Crítica (9) | 0.64% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | |
| Analizada | Crítica (9.1) | 0.47% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | |
| Modificada | Media (5.9) | 0.30% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window. | |
| Analizada | Alta (7.5) | 0.69% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to… | |
| Analizada | Crítica (9.8) | 0.94% | — | IBM Websphere Application Server | 26/5/2026 | 23/7/2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request. | |
| Analizada | Alta (7.5) | 0.37% | — | IBM Websphere Application Server | 26/5/2026 | 23/7/2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request. | |
| Analizada | Media (4.3) | 0.29% | — | SAP Netweaver Application Server Abap | 14/5/2026 | 17/6/2026 | Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a… |