Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 29/9/2026 | 2/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| En análisis | Alta (8.8) | 0.41% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | |
| En análisis | Alta (8.8) | 0.75% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | |
| En análisis | Alta (8.8) | 0.75% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 26/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| En análisis | Alta (8.8) | 0.92% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | |
| En análisis | Alta (8.8) | 0.98% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 26/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection. | |
| En análisis | Alta (7.7) | 0.28% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| En análisis | Alta (7.7) | 0.23% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments. | |
| En análisis | Alta (8.8) | 0.33% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts. | |
| En análisis | Alta (8.8) | 0.94% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| En análisis | Alta (8.8) | 0.54% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 26/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation. | |
| En análisis | Alta (8.8) | 0.94% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 23/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.58% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.96% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 1.7% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 25/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection. | |
| En análisis | Crítica (9.9) | 0.45% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 22/9/2026 | 23/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cloud PAK FOR Data | 18/9/2026 | 22/9/2026 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Cloud PAK FOR Data | 18/9/2026 | 22/9/2026 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Pendiente de análisis | Alta (8.2) | 0.21% | — | IBM Cloud PAK FOR Data SystemAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols. | |
| En análisis | Alta (8.8) | 0.42% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 14/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property. | |
| En análisis | Alta (8.8) | 0.91% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 14/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | |
| En análisis | Alta (7.7) | 0.34% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 14/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| En análisis | Alta (8.8) | 0.54% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 14/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. | |
| En análisis | Crítica (9.9) | 0.43% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 14/9/2026 | 16/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. |