Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
5032 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability. | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-rbAI | 14/9/2026 | 25/9/2026 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-javaAI | 14/9/2026 | 30/9/2026 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage… | |
| Aplazada | Media (4.3) | 1.1% | — | DataeaseAI | 14/9/2026 | 22/9/2026 | A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component. | |
| Aplazada | Media (5.1) | 0.35% | — | DataeaseAI | 13/9/2026 | 15/9/2026 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument… | |
| Pendiente de análisis | Alta (7.5) | 0.58% | — | Fasterxml Jackson-databindAI | 11/9/2026 | 18/9/2026 | jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with… | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | Pentaho Data IntegrationAI | 11/9/2026 | 18/9/2026 | The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. | |
| Analizada | Crítica (9.6) | 0.54% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | |
| Analizada | Media (6.5) | 0.61% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.79% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Media (6.5) | 0.77% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |
| Analizada | Alta (8.1) | 0.64% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.5) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | |
| Analizada | Alta (7.7) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection… | |
| Analizada | Alta (8.5) | 0.29% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift… | |
| Analizada | Alta (8.5) | 0.38% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. | |
| Analizada | Media (5) | 0.31% | — | IBM Datastage ON Cloud PAK FOR Data | 10/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. |