Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
9523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.35% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers. | |
| Pendiente de análisis | Crítica (9.9) | 0.37% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | |
| Analizada | Alta (8.8) | 0.37% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths. | |
| En análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 30/9/2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI | 18/9/2026 | 21/9/2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling. | |
| Pendiente de análisis | Crítica (10) | 0.57% | — | IBM MQ ApplianceAI | 18/9/2026 | 21/9/2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | |
| Pendiente de análisis | Alta (7.5) | 0.27% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation. | |
| Analizada | Alta (8.8) | 0.28% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers. | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | IBM MQ ConsoleAI | 18/9/2026 | 18/9/2026 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks. | |
| Analizada | Crítica (9.8) | 0.45% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | IBM ControllerAI | 18/9/2026 | 18/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size. | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI | 18/9/2026 | 22/9/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 18/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system. | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | IBM Ts4300AI | 18/9/2026 | 22/9/2026 | IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency. | |
| Pendiente de análisis | Media (5.9) | 0.17% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 21/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | IBM QradarAI | 18/9/2026 | 18/9/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. | |
| Pendiente de análisis | Crítica (10) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 21/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cloud PAK FOR Data | 18/9/2026 | 22/9/2026 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Cloud PAK FOR Data | 18/9/2026 | 22/9/2026 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI | 18/9/2026 | 18/9/2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of… | |
| Pendiente de análisis | Media (5.9) | 0.17% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 28/9/2026 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. |