Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
21.069 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.61% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | |
| Analizada | Alta (7.5) | 0.45% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. | |
| Analizada | Media (6.1) | 0.30% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. | |
| Analizada | Crítica (9.8) | 0.97% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.53% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | |
| Analizada | Media (6.5) | 0.37% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. | |
| Analizada | Crítica (9.8) | 0.47% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |
| Modificada | Alta (8.1) | 0.39% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |
| Analizada | Alta (8.2) | 0.43% | — | Appium Java-client | 28/7/2026 | 7/8/2026 | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 28/7/2026 | 28/7/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their… | |
| Aplazada | Crítica (9.4) | 0.85% | — | Dynamicsoft AppengineAI | 28/7/2026 | 9/9/2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication.… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | 3DS 3dexperienceAI3DS Station Launcher APPAI | 28/7/2026 | 30/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 0.52% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie. | |
| Analizada | Alta (8.8) | 0.53% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains… | |
| Analizada | Crítica (9.8) | 0.33% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often,… | |
| Analizada | Alta (8.8) | 0.53% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases.… | |
| Analizada | Crítica (9.8) | 0.56% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential… | |
| Analizada | Alta (8.8) | 0.43% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 28/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Media (5.5) | 0.17% | — | Apple Macos | 27/7/2026 | 28/7/2026 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory. | |
| Analizada | Crítica (9.8) | 0.66% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 29/7/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap… | |
| Modificada | Crítica (9.8) | 0.78% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. |