Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

9523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.35%—IBM MQ18/9/202623/9/2026
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Pendiente de análisisCrítica (9.9)0.37%—IBM MQAIHPE NonstopAI18/9/202619/9/2026
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
AnalizadaAlta (8.8)0.37%—IBM MQ18/9/202623/9/2026
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
En análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202630/9/2026
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
Pendiente de análisisAlta (7.5)0.37%—IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI18/9/202621/9/2026
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
Pendiente de análisisCrítica (10)0.57%—IBM MQ ApplianceAI18/9/202621/9/2026
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Pendiente de análisisAlta (7.5)0.27%—IBM MQAIHPE NonstopAI18/9/202619/9/2026
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
AnalizadaAlta (8.8)0.28%—IBM MQ18/9/202623/9/2026
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
Pendiente de análisisAlta (7.1)0.23%—IBM MQ ConsoleAI18/9/202618/9/2026
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
AnalizadaCrítica (9.8)0.45%—IBM MQ18/9/202623/9/2026
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
Pendiente de análisisMedia (5.9)0.16%—IBM ControllerAI18/9/202619/9/2026
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Pendiente de análisisMedia (5.4)0.25%—IBM ControllerAI18/9/202618/9/2026
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
Pendiente de análisisMedia (6.1)0.20%—IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI18/9/202622/9/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
Pendiente de análisisMedia (4.3)0.21%—IBM Cognos AnalyticsAI18/9/202618/9/2026
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
Pendiente de análisisMedia (4.3)0.26%—IBM Ts4300AI18/9/202622/9/2026
IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Pendiente de análisisMedia (5.9)0.17%—IBM Cognos AnalyticsAI18/9/202621/9/2026
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
Pendiente de análisisMedia (6.5)0.27%—IBM QradarAI18/9/202618/9/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Pendiente de análisisCrítica (10)0.18%—IBM Common Licensing AgentAIIBM ARTAI18/9/202621/9/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AnalizadaAlta (8.8)0.44%—IBM Cloud PAK FOR Data18/9/202622/9/2026
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (7.5)0.46%—IBM Cloud PAK FOR Data18/9/202622/9/2026
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Pendiente de análisisMedia (5.3)0.24%—IBM ControllerAI18/9/202619/9/2026
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Pendiente de análisisMedia (5.3)0.25%—IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI18/9/202618/9/2026
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of…
Pendiente de análisisMedia (5.9)0.17%—IBM Cognos AnalyticsAI18/9/202628/9/2026
IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
Pendiente de análisisAlta (7.1)0.36%—IBM Business Automation WorkflowAI15/9/202616/9/2026
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
Pendiente de análisisMedia (5.4)0.17%—IBM Business Automation WorkflowAI15/9/202616/9/2026
IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.