Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Crítica (10) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 21/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Pendiente de análisis | Media (6.2) | 0.12% | — | IBM Common Licensing AgentAIIBM ARTAI | 14/9/2026 | 16/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values,… | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | IBM Common Licensing AgentAIIBM ARTAI | 10/9/2026 | 11/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Common Licensing | 26/1/2025 | 17/6/2026 | IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism. | |
| Analizada | Media (5.5) | 0.14% | — | IBM Common Licensing | 26/1/2025 | 17/6/2026 | IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. | |
| Modificada | Media (4.8) | 0.26% | — | IBM Common Licensing | 13/8/2024 | 17/6/2026 | IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348. | |
| Analizada | Alta (7.5) | 0.49% | — | IBM Common Licensing | 13/8/2024 | 17/6/2026 | IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895. | |
| Analizada | Baja (3.3) | 0.19% | — | IBM Common Licensing | 20/2/2024 | 17/6/2026 | IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337. | |
| Modificada | Media (6.9) | 0.37% | — | IBM Rational ClearcaseIBM Rational ClearquestIBM Rational Common Licensing | 29/3/2011 | 16/6/2026 | Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone. |