Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
3798 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Pendiente de análisis | Media (6.3) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history).… | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a… | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 7/8/2026 | 17/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Safetipin Android ApplicationAI | 5/8/2026 | 1/10/2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | |
| Aplazada | Alta (8.1) | 0.39% | — | Sirengps Android ApplicationAI | 5/8/2026 | 1/10/2026 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is… | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Application Gateway Operator | 5/8/2026 | 10/8/2026 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Websphere Application Server | 5/8/2026 | 10/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | |
| Analizada | Media (4.3) | 0.19% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Analizada | Alta (8.5) | 0.58% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 30/7/2026 | 12/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |
| Analizada | Alta (8.8) | 0.15% | — | IBM Websphere Application Server | 29/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Crítica (9.8) | 0.53% | — | IBM Websphere Application Server | 29/7/2026 | 4/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 6/8/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. |