Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
9523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.96% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 1.7% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection. | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | IBM ConcertAI | 22/9/2026 | 23/9/2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Crítica (9.9) | 0.45% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Pendiente de análisis | Media (6.2) | 0.12% | — | IBM ConcertAI | 22/9/2026 | 23/9/2026 | IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | IBM ConcertAI | 22/9/2026 | 23/9/2026 | IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | IBM ConcertAI | 22/9/2026 | 23/9/2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. | |
| Analizada | Alta (7.6) | 0.55% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (8.1) | 0.63% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation. | |
| Analizada | Alta (8.9) | 0.53% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | |
| Analizada | Alta (7.7) | 0.47% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| Analizada | Alta (7.2) | 0.87% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.1) | 0.50% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.24% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting… | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Alta (8.1) | 0.29% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. | |
| Analizada | Crítica (9.9) | 0.47% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system. | |
| Analizada | Alta (8.1) | 0.22% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. | |
| Analizada | Alta (7.6) | 0.39% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | |
| Analizada | Crítica (9.9) | 0.56% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. | |
| Analizada | Alta (8.9) | 0.53% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |