Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.30% | — | GratisfactionAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Booking ActivitiesAI | 30/9/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Aplazada | Alta (7.6) | 0.31% | — | WP Activity LOGAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Qodeinteractive QI Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Apache Activemq ArtemisAI | 28/9/2026 | 29/9/2026 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated… | |
| Pendiente de análisis | Media (6.2) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | |
| Pendiente de análisis | Alta (8.2) | 0.30% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. | |
| Pendiente de análisis | Media (4.4) | 0.09% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. | |
| Pendiente de análisis | Alta (7.3) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool… | |
| Pendiente de análisis | Crítica (9.3) | 0.19% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator… | |
| Pendiente de análisis | Media (5.4) | 0.15% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential… | |
| Pendiente de análisis | Alta (8.8) | 0.25% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAIIBM PaydirAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to… | |
| Pendiente de análisis | Alta (7.3) | 0.26% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function. | |
| Pendiente de análisis | Alta (7.4) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |
| Pendiente de análisis | Alta (8.1) | 0.25% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key. | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. | |
| Pendiente de análisis | Alta (7.1) | 0.18% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | |
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Pendiente de análisis | Alta (7.4) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | |
| Pendiente de análisis | Baja (3.7) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. | |
| Pendiente de análisis | Crítica (9.9) | 0.53% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |