Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.46% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| Analizada | Alta (7.2) | 0.87% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.1) | 0.50% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.25% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting… | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (8.1) | 0.31% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. | |
| Analizada | Crítica (9.9) | 0.47% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system. | |
| Analizada | Alta (8.1) | 0.26% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. | |
| Analizada | Alta (7.6) | 0.41% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | |
| Analizada | Crítica (9.9) | 0.59% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. | |
| Analizada | Alta (8.9) | 0.52% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | |
| Analizada | Crítica (9.1) | 0.43% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (7.2) | 1.5% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command… | |
| Analizada | Alta (8.9) | 0.52% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | |
| Analizada | Crítica (9.9) | 0.62% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (7.4) | 0.34% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | |
| Analizada | Alta (8.8) | 0.42% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system… | |
| Analizada | Crítica (9) | 0.61% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | |
| En análisis | Crítica (9.8) | 0.79% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. | |
| En análisis | Alta (7.6) | 0.49% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability. | |
| En análisis | Alta (7.8) | 0.14% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| En análisis | Alta (8.1) | 0.62% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| En análisis | Media (5.9) | 0.32% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation. |