Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.42% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability. | |
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the… | |
| Aplazada | Media (5.1) | 0.35% | — | Tduckcloud Tduck-platformAI | 13/9/2026 | 14/9/2026 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is… | |
| Aplazada | Alta (8.6) | 0.43% | — | Yogeta WP CloudAI | 12/9/2026 | 14/9/2026 | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive… | |
| Aplazada | Media (6.5) | 0.31% | — | Simple Captcha With Cloudflare TurnstileAI | 11/9/2026 | 11/9/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Analizada | Crítica (9.6) | 0.54% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | |
| Analizada | Media (6.5) | 0.61% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.79% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Alta (8.1) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.5) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | |
| Analizada | Alta (7.7) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection… | |
| Analizada | Alta (8.5) | 0.29% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift… | |
| Analizada | Alta (8.5) | 0.38% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. | |
| Analizada | Media (5) | 0.31% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. | |
| Analizada | Crítica (9.1) | 0.51% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. | |
| Analizada | Alta (7.1) | 0.20% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery. | |
| Analizada | Media (6.5) | 0.38% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization. |