Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.34% | — | IBM Application Gateway Operator | 5/8/2026 | 10/8/2026 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.5) | 0.13% | — | IBM Application Gateway | 3/6/2025 | 17/6/2026 | IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. | |
| Analizada | Crítica (10) | 0.81% | — | IBM Application GatewayIBM Security Verify Access | 4/4/2024 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584. | |
| Modificada | Media (5.4) | 0.46% | — | IBM Application Gateway | 28/9/2022 | 17/6/2026 | IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965. | |
| Modificada | Alta (7.2) | 0.44% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. | |
| Modificada | Crítica (9.8) | 0.45% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | |
| Modificada | Alta (7.5) | 2.5% | — | IBM Application GatewayIBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Application GatewayIBM Security Verify Access | 1/6/2021 | 17/6/2026 | IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. | |
| Modificada | Alta (9.3) | 46% | — | Microsoft Intelligent Application Gateway 2007 | 16/4/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods. |