Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.37% | — | IBM Websphere Application Server | 23/4/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured. | |
| Analizada | Media (5.4) | 0.29% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. | |
| Analizada | Alta (7.2) | 0.56% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server. | |
| Analizada | Crítica (9.8) | 0.18% | — | IBM Websphere Application Server | 3/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. | |
| Analizada | Media (4.9) | 0.33% | — | IBM Websphere Application Server | 17/2/2026 | 17/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings. | |
| Analizada | Alta (7.6) | 0.48% | — | IBM Websphere Application Server | 2/2/2026 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Websphere Application Server | 8/12/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious… | |
| Analizada | Media (4.9) | 0.32% | — | IBM Websphere Application Server | 29/9/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources. | |
| Modificada | Alta (7.5) | 0.45% | — | IBM Websphere Application Server | 14/8/2025 | 17/6/2026 | IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Websphere Application Server | 14/8/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections. | |
| Analizada | Media (4.8) | 0.18% | — | IBM Websphere Application Server | 12/8/2025 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Websphere Application Server | 12/8/2025 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration | |
| Analizada | Alta (7.5) | 0.42% | — | IBM Websphere Application Server | 7/8/2025 | 17/6/2026 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 16/7/2025 | 17/6/2026 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources. | |
| Analizada | Crítica (9.8) | 13% | — | IBM Websphere Application Server | 25/6/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. | |
| Analizada | Alta (7.6) | 0.24% | — | IBM Websphere Application Server | 14/5/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Baja (2.7) | 0.34% | — | IBM Websphere Application Server | 22/4/2025 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (4.8) | 0.23% | — | IBM Websphere Application Server | 11/11/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.5) | 0.44% | — | IBM Websphere Application Server | 4/11/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Media (5.5) | 0.44% | — | IBM Websphere Application Server | 16/10/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Media (4.8) | 0.25% | — | IBM Websphere Application Server | 16/10/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 15/10/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service. | |
| Analizada | Media (4.8) | 0.25% | — | IBM Websphere Application Server | 30/9/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.26% | — | IBM Websphere Application Server | 14/8/2024 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713. |