Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5029 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.8)0.78%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
En análisisAlta (8.8)0.50%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
AnalizadaCrítica (9.6)0.61%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
AnalizadaCrítica (9.8)0.69%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code…
AnalizadaAlta (7.2)1.5%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to…
AnalizadaAlta (8.8)0.43%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the…
AnalizadaAlta (7.2)1.3%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
AnalizadaCrítica (9.8)0.85%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
AnalizadaAlta (8.8)0.43%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality,…
AnalizadaAlta (8.6)0.37%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and…
AnalizadaAlta (8.8)0.36%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (8.8)0.63%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
AnalizadaCrítica (9.8)0.56%—IBM Guardium Data Protection18/9/20266/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the…
AnalizadaAlta (8.8)0.44%—IBM Cloud PAK FOR Data18/9/202622/9/2026
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (7.5)0.46%—IBM Cloud PAK FOR Data18/9/202622/9/2026
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Pendiente de análisisAlta (7.7)1.5%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Pendiente de análisisAlta (7.5)1.1%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
AnalizadaAlta (8.1)0.37%—Microsoft Dataverse17/9/202625/9/2026
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.5)0.79%—Datadog Dd-trace-cppAI17/9/202624/9/2026
dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even though those limits are enforced during injection. A remote unauthenticated attacker…
Pendiente de análisisAlta (7.5)0.68%—Datadog PHP TracerAI17/9/202623/9/2026
The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES. A remote…
AplazadaCrítica (9.8)0.32%—Maildata Email Archiving SystemAI17/9/202622/9/2026
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
AplazadaMedia (5.3)0.26%—DatatablesAIWwbn AvideoAI16/9/202622/9/2026
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings…
AplazadaAlta (7.7)0.69%—Kedro DatasetsAIPytorchAI16/9/202630/9/2026
Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On PyTorch versions earlier than 2.6, a…
AplazadaAlta (8.8)0.54%—DatagearAI16/9/202623/9/2026
DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud…
AplazadaBaja (2.7)0.30%—WP AMP Schema AND Structured Data FOR WP AND AMPAI16/9/202617/9/2026
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts.
Orbitaley — Vulnerabilidades