Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
9598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.38% | — | IBM Guardium Data Protection | 27/5/2026 | 17/6/2026 | IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server | 27/5/2026 | 17/6/2026 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd… | |
| Analizada | Alta (8.8) | 0.61% | — | IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server | 27/5/2026 | 17/6/2026 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute… | |
| Analizada | Crítica (9.8) | 0.94% | — | IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server | 27/5/2026 | 17/6/2026 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service… | |
| Modificada | Crítica (9.1) | 0.50% | — | IBM Aspera High-speed Transfer Server FOR Cloud PAK FOR Integration | 27/5/2026 | 17/6/2026 | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place. | |
| Analizada | Alta (7.8) | 0.18% | — | IBM Operations Analytics LOG Analysis | 27/5/2026 | 17/6/2026 | IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication. | |
| Analizada | Media (5.3) | 0.40% | — | IBM Openbmc | 27/5/2026 | 17/6/2026 | IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users. | |
| Analizada | Alta (7.5) | 0.32% | — | IBM DB2 | 27/5/2026 | 17/6/2026 | IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. | |
| Analizada | Media (6.5) | 0.42% | — | IBM I | 27/5/2026 | 17/6/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements. | |
| Analizada | Media (5.5) | 0.14% | — | IBM DB2 | 27/5/2026 | 17/6/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables. | |
| Analizada | Alta (7.5) | 0.42% | — | IBM DB2 | 27/5/2026 | 17/6/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. | |
| Analizada | Alta (7.5) | 0.30% | — | IBM DB2 | 27/5/2026 | 17/6/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap. | |
| Modificada | Media (5.9) | 0.30% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window. | |
| Modificada | Media (5.5) | 0.14% | — | IBM APP Connect Enterprise | 27/5/2026 | 17/6/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (8.8) | 0.33% | — | IBM Controller | 27/5/2026 | 17/6/2026 | IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | |
| Analizada | Alta (7.5) | 0.69% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to… | |
| Analizada | Media (6.5) | 0.42% | — | IBM Cloud Application Performance Managemen | 27/5/2026 | 17/6/2026 | IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Netezza Performance Server Replication Services | 27/5/2026 | 17/6/2026 | IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also… | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Infosphere Optim Test Data Fabrication | 27/5/2026 | 17/6/2026 | IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on… | |
| Pendiente de análisis | Media (5.1) | 0.13% | — | IBM MQAIIBM MQ OperatorAI | 27/5/2026 | 17/6/2026 | IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1,… | |
| Analizada | Alta (7.5) | 0.36% | — | IBM DB2 | 27/5/2026 | 17/6/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled. | |
| Analizada | Alta (8.2) | 0.31% | — | IBM Cognos AnalyticsIBM Cognos Transformer | 27/5/2026 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead… | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Qradar Security Information AND Event Manager | 27/5/2026 | 17/6/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system. | |
| Analizada | Crítica (9.8) | 0.36% | — | IBM Operations Analytics LOG Analysis | 27/5/2026 | 17/6/2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to… | |
| Analizada | Media (5.3) | 0.39% | — | IBM Security Directory Integrator | 27/5/2026 | 17/6/2026 | IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |