Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5399 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.42%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
AplazadaBaja (2.1)0.37%—Wxiaoqi Spring Cloud PlatformAI13/9/202615/9/2026
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit…
AplazadaBaja (2.1)0.37%—Wxiaoqi Spring Cloud PlatformAI13/9/202614/9/2026
A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the…
AplazadaMedia (5.1)0.35%—Tduckcloud Tduck-platformAI13/9/202614/9/2026
A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is…
AplazadaAlta (8.6)0.43%—Yogeta WP CloudAI12/9/202614/9/2026
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive…
AplazadaMedia (6.5)0.31%—Simple Captcha With Cloudflare TurnstileAI11/9/202611/9/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
Pendiente de análisisAlta (8.7)0.27%—Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI11/9/202611/9/2026
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users…
AnalizadaCrítica (9.6)0.54%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
AnalizadaMedia (6.5)0.61%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.79%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.8)0.64%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaMedia (6.5)0.77%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
AnalizadaMedia (6.5)0.77%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
AnalizadaAlta (8.1)0.64%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
AnalizadaAlta (8.8)0.81%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
AnalizadaAlta (8.5)0.55%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
AnalizadaAlta (7.7)0.34%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection…
AnalizadaAlta (8.5)0.29%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift…
AnalizadaAlta (8.5)0.38%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
AnalizadaMedia (5)0.31%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
AnalizadaCrítica (9.1)0.51%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
AnalizadaAlta (7.1)0.20%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
AnalizadaMedia (6.5)0.38%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.