Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

248 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.54%—IBM ViosIBM AIX13/11/202517/6/2026
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
AnalizadaCrítica (9.8)0.67%—IBM ViosIBM AIX13/11/202517/6/2026
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
AnalizadaCrítica (9.1)0.49%—IBM ViosIBM AIX13/11/202517/6/2026
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
AnalizadaAlta (8.1)0.30%—IBM ViosIBM AIX13/11/202517/6/2026
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
AnalizadaAlta (7.3)0.28%—X.org X ServerX.org XwaylandIBM ViosIBM AIX+730/10/20251/7/2026
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
AnalizadaAlta (7.3)0.30%—X.org X ServerX.org XwaylandIBM ViosIBM AIX+730/10/20251/7/2026
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
AplazadaMedia (5.3)0.36%—Coordinadora Mercantil S.A Envios Coordinadora WoocommerceAI22/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Coordinadora Mercantil S.A. Envíos Coordinadora Woocommerce coordinadora allows Retrieve Embedded Sensitive Data.This issue affects Envíos Coordinadora Woocommerce: from n/a through <= 1.1.32.
AnalizadaMedia (5.5)0.12%—IBM ViosIBM AIX16/9/202517/6/2026
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
AplazadaAlta (7)0.62%—ViostorAI29/8/202517/6/2026
A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and…
AnalizadaBaja (1.9)0.21%—Xmlsoft Libxml2Siemens Ruggedcom Rst2428p FirmwareIBM ViosIBM AIX8/8/20251/7/2026
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be…
AplazadaAlta (8.5)0.37%—Pakkemx Pakke EnviosAI16/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos pakke allows SQL Injection.This issue affects Pakke Envíos: from n/a through <= 1.0.2.
AnalizadaAlta (8.4)0.22%—IBM ViosIBM AIX10/6/202517/6/2026
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
AnalizadaMedia (5.5)0.13%—IBM ViosIBM AIX25/12/202417/6/2026
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
ModificadaMedia (5.5)0.15%—IBM ViosIBM AIX25/12/202417/6/2026
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
AplazadaMedia (6.1)0.36%—Pkt1 Centro DE EnviosAI20/12/202417/6/2026
The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'error' parameters in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaAlta (7.8)0.23%—IBM ViosIBM AIX7/12/202417/6/2026
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
AnalizadaAlta (8.4)0.23%—IBM ViosIBM AIX16/5/202417/6/2026
IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
AnalizadaAlta (7.8)0.15%—IBM ViosIBM AIX7/5/202417/6/2026
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.
AnalizadaAlta (8.4)0.27%—IBM ViosIBM AIX22/2/202417/6/2026
IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.
ModificadaMedia (5.5)0.17%—IBM ViosIBM AIX11/1/202417/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969.
ModificadaMedia (5.5)0.17%—IBM ViosIBM AIX11/1/202417/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.
ModificadaMedia (5.5)0.17%—IBM ViosIBM AIX11/1/202417/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 267973.
ModificadaMedia (5.5)0.17%—IBM ViosIBM AIX11/1/202417/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 267971.
ModificadaMedia (5.5)0.23%—IBM ViosIBM AIX19/12/202317/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970.
ModificadaAlta (7.8)0.24%—IBM ViosIBM AIX13/12/202317/6/2026
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.
Orbitaley — Vulnerabilidades