Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
9597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | IBM DB2 | 30/4/2026 | 7/10/2026 | IBM Db2 11.5.0 hasta 11.5.9, y 12.1.0 hasta 12.1.3 para Linux, UNIX y Windows (incluye DB2 Connect Servidor) podría permitir a un usuario autenticado causar una denegación de servicio utilizando una consulta SQL especialmente diseñada debido a una asignación incorrecta de recursos del sistema. | |
| Analizada | Media (5.3) | 0.22% | — | IBM DB2 | 30/4/2026 | 7/10/2026 | IBM Db2 11.5.0 hasta 11.5.9, y 12.1.0 hasta 12.1.3 para Linux, UNIX y Windows (incluye Db2 Connect servidor) podría permitir a un usuario autenticado causar una denegación de servicio debido a una neutralización incorrecta de elementos especiales en la lógica de consulta de datos cuando existen ciertas configuraciones. | |
| Analizada | Alta (7.5) | 0.94% | — | Xmlsoft Libxml2Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container Platform+3 | 23/4/2026 | 31/8/2026 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the… | |
| Analizada | Crítica (9.8) | 0.54% | — | IBM Total Storage Service ConsoleIBM Ts4500 IMC | 23/4/2026 | 17/6/2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Media (6.5) | 0.23% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 23/4/2026 | 17/6/2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt… | |
| Analizada | Media (4.8) | 0.24% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.8) | 0.24% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.9) | 0.42% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |
| Analizada | Media (5.9) | 0.37% | — | IBM Websphere Application Server | 23/4/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured. | |
| Modificada | Media (4.8) | 0.19% | — | IBM Guardium KEY Lifecycle Manager | 23/4/2026 | 17/6/2026 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines… | |
| Analizada | Media (6.5) | 0.33% | — | IBM DB2 | 23/4/2026 | 17/6/2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic. | |
| Analizada | Media (4.9) | 0.30% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel. | |
| Analizada | Media (4.3) | 0.20% | — | IBM Guardium Data Protection | 23/4/2026 | 17/6/2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel. | |
| Analizada | Alta (7.2) | 0.34% | — | IBM Security Verify Directory | 22/4/2026 | 7/10/2026 | IBM Security Verify Directory (Contenedor) 10.0.0 hasta 10.0.0.3 IBM Security Verify Directory podría ser vulnerable a la carga de archivos maliciosos al no validar el tipo de archivo. Un usuario privilegiado podría cargar archivos maliciosos en el sistema que pueden ser enviados a las víctimas para realizar ataques… | |
| Analizada | Media (5.5) | 0.16% | — | IBM Tivoli Netcool/impact | 8/4/2026 | 24/7/2026 | IBM Tivoli Netcool Impact 7.1.0.0 hasta 7.1.0.37 almacena información sensible en archivos de registro que podría ser leída por un usuario local. | |
| Analizada | Alta (7.8) | 0.23% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 8/4/2026 | 25/7/2026 | IBM Verify Identity Access Contenedor 11.0 hasta 11.0.2 y IBM Security Verify Access Contenedor 10.0 hasta 10.0.9.1 y IBM Verify Identity Access 11.0 hasta 11.0.2 y IBM Security Verify Access 10.0 hasta 10.0.9.1 podrían permitir a un usuario autenticado localmente escalar sus privilegios a root debido a la ejecución… | |
| Analizada | Alta (7.2) | 0.20% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 8/4/2026 | 25/7/2026 | IBM Verify Identity Access Contenedor 11.0 hasta 11.0.2 y IBM Security Verify Access Contenedor 10.0 hasta 10.0.9.1 y IBM Verify Identity Access 11.0 hasta 11.0.2 y IBM Security Verify Access 10.0 hasta 10.0.9.1 permite a un atacante contactar puntos finales de autenticación internos que están protegidos por el Proxy… | |
| Analizada | Alta (7.9) | 0.18% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 8/4/2026 | 24/7/2026 | IBM Verify Identity Access Contenedor 11.0 hasta 11.0.2 y IBM Security Verify Access Contenedor 10.0 hasta 10.0.9.1 y IBM Verify Identity Access 11.0 hasta 11.0.2 y IBM Security Verify Access 10.0 hasta 10.0.9.1 podrían permitir a un usuario autenticado localmente ejecutar scripts maliciosos desde fuera de su esfera… | |
| Analizada | Media (6.2) | 0.14% | — | IBM Concert | 7/4/2026 | 24/7/2026 | IBM Concert 1.0.0 a través de 2.2.0 crea archivos temporales con nombres predecibles, lo que permite a usuarios locales sobrescribir archivos arbitrarios mediante un ataque de enlace simbólico. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Content Navigator | 2/4/2026 | 17/6/2026 | IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Analizada | Media (4.3) | 0.19% | — | IBM Maximo Application Suite | 1/4/2026 | 17/6/2026 | IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and… | |
| Analizada | Media (5.4) | 0.15% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 1/4/2026 | 17/6/2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows certificate listings retrieved via a browser session to return a JSON payload while… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 hasta 1.11.0 no limita adecuadamente la frecuencia con la que un usuario autenticado puede enviar correos electrónicos, lo que podría resultar en una inundación de correos electrónicos o una denegación de servicio. | |
| Analizada | Media (6.1) | 0.24% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 hasta 1.11.0 es vulnerable a la inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, al ser visto, se ejecutaría en el navegador web de la víctima dentro del contexto de seguridad del sitio de alojamiento. |