Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.40% | — | IBM Websphere Application Server | 27/4/2023 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Websphere Application Server | 2/4/2023 | 17/6/2026 | IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416. | |
| Modificada | Crítica (9.8) | 1.9% | — | IBM Websphere Application Server | 3/2/2023 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513. | |
| Modificada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 26/1/2023 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045. | |
| Modificada | Media (5.5) | 0.20% | — | Websphere Automation FOR IBM Cloud PAK FOR Watson Aiops | 1/12/2022 | 17/6/2026 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829. | |
| Modificada | Media (6.5) | 0.17% | — | Websphere Automation FOR IBM Cloud PAK FOR Watson Aiops | 1/12/2022 | 17/6/2026 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827. | |
| Modificada | Media (5.4) | 0.40% | — | IBM Websphere Application Server | 11/11/2022 | 17/6/2026 | IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588. | |
| Modificada | Media (5.9) | 0.51% | — | IBM Websphere Application Server | 3/11/2022 | 17/6/2026 | "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762." | |
| Modificada | Alta (8.8) | 0.32% | — | Websphere Automation FOR IBM Cloud PAK FOR Watson Aiops | 7/10/2022 | 17/6/2026 | IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Websphere MQ | 29/9/2022 | 16/6/2026 | IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on a SVRCONN channel and flood the queue manager. | |
| Modificada | Media (6.5) | 0.34% | — | IBM Websphere Application Server | 28/9/2022 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data. | |
| Modificada | Media (5.4) | 0.51% | — | IBM Websphere Application Server | 13/9/2022 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714. | |
| Modificada | Media (5.4) | 0.58% | — | IBM Websphere Application Server | 9/9/2022 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and… | |
| Modificada | Media (6.1) | 0.58% | — | IBM Websphere Application Server | 14/7/2022 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Websphere Application Server | 14/7/2022 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347. | |
| Modificada | Alta (8.8) | 0.85% | — | IBM Open LibertyIBM Websphere Application Server | 8/7/2022 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604. | |
| Modificada | Media (5.9) | 0.60% | — | IBM Websphere Application Server | 20/5/2022 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904. | |
| Modificada | Media (6.5) | 0.65% | — | IBM Open LibertyIBM Websphere Application Server | 17/5/2022 | 17/6/2026 | IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603. | |
| Modificada | Media (6.5) | 0.74% | — | IBM Websphere Application Server | 13/5/2022 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Websphere Application Server | 24/2/2022 | 17/6/2026 | IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click… | |
| Modificada | Alta (8.8) | 2.0% | — | IBM Websphere Application Server | 25/1/2022 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Websphere Application Server | 19/1/2022 | 17/6/2026 | IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Websphere Application Server | 9/12/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405. | |
| Modificada | Media (5.5) | 0.17% | — | IBM MQIBM Websphere MQ | 16/11/2021 | 17/6/2026 | IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Websphere Application Server | 16/9/2021 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202. |