Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.34%—IBM Application Gateway Operator5/8/202610/8/2026
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
AnalizadaMedia (5.4)0.19%—IBM Application Gateway20/1/202617/6/2026
IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (5.4)0.17%—IBM Application Gateway20/1/202617/6/2026
IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (5.5)0.13%—IBM Application Gateway3/6/202517/6/2026
IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
AnalizadaCrítica (10)0.81%—IBM Application GatewayIBM Security Verify Access4/4/202417/6/2026
IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.
ModificadaMedia (5.4)0.46%—IBM Application Gateway28/9/202217/6/2026
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.
ModificadaAlta (7.2)0.44%—Amodat Mobile Application Gateway13/6/202217/6/2026
attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
ModificadaCrítica (9.8)0.45%—Amodat Mobile Application Gateway13/6/202217/6/2026
The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--
ModificadaAlta (7.5)2.5%—IBM Application GatewayIBM Security Verify Access1/6/202117/6/2026
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
ModificadaBaja (3.3)0.27%—IBM Application GatewayIBM Security Verify Access1/6/202117/6/2026
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
ModificadaAlta (9.3)46%—Microsoft Intelligent Application Gateway 200716/4/200916/6/2026
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.