Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

11.351 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (7.6)0.19%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
En análisisMedia (6.5)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.
En análisisAlta (8.5)0.42%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
En análisisAlta (8.2)0.41%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
En análisisAlta (7.9)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
En análisisAlta (8.8)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.
En análisisAlta (8.5)0.29%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
En análisisCrítica (9.1)0.38%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
En análisisAlta (8.8)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
En análisisAlta (8.8)0.10%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
En análisisAlta (8.8)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
En análisisAlta (8.8)0.50%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
En análisisCrítica (9.1)0.35%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
En análisisMedia (5.3)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by…
En análisisAlta (7.3)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
AplazadaAlta (8.4)0.13%—Apache Http ServerAIOpensslAI22/9/202623/9/2026
The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.
AnalizadaMedia (5.4)0.21%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux22/9/20267/10/2026
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued…
Pendiente de análisisCrítica (9.6)0.38%💥 PoCFortinet Fortipam Chrome ExtensionAI22/9/202626/9/2026
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
Pendiente de análisisCrítica (9.4)0.53%—Openstack OctaviaAI21/9/202624/9/2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed…
Pendiente de análisisCrítica (9.4)0.53%—Openstack OctaviaAI21/9/202622/9/2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw…
Pendiente de análisisAlta (7.4)0.31%—Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI21/9/202624/9/2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to…
Pendiente de análisisAlta (8.8)0.65%—Redhat Openshift Container PlatformAIKubernetes Cri-oAI21/9/20261/10/2026
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the…
AplazadaBaja (2)0.34%—Piskvorky GensimAI20/9/202621/9/2026
A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely. The exploit has been made available to the…
Pendiente de análisisCrítica (9.3)0.80%—Openshift ConsoleAI18/9/20261/10/2026
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial…
Pendiente de análisisAlta (7.2)0.41%—Openstack BlazarAI18/9/202622/9/2026
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it…