Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
9523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | IBM Sterling File GatewayAI | 18/9/2026 | 22/9/2026 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. | |
| Pendiente de análisis | Media (6.4) | 0.22% | — | IBM IAI | 18/9/2026 | 22/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands. | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | IBM Platform RTMAI | 18/9/2026 | 22/9/2026 | IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Pendiente de análisis | Media (5.4) | 0.19% | — | IBM IAI | 18/9/2026 | 23/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands. | |
| Pendiente de análisis | Alta (8.1) | 0.44% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data. | |
| Pendiente de análisis | Alta (8.1) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values. | |
| Pendiente de análisis | Alta (8.8) | 0.40% | — | IBM MQAI | 18/9/2026 | 22/9/2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing. | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data. | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Baja (3.7) | 0.26% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. | |
| Analizada | Media (5.3) | 0.16% | — | IBM Websphere Application Server | 18/9/2026 | 24/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Media (4.3) | 0.18% | — | IBM Websphere Application ServerAI | 18/9/2026 | 19/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | |
| En análisis | Alta (8.8) | 0.33% | — | IBM MQAI | 18/9/2026 | 19/9/2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures. | |
| Analizada | Alta (8.8) | 0.34% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing. |