Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.3)0.06%—IBM DB2 Mirror FOR I24/9/202629/9/2026
IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
Pendiente de análisisMedia (5.4)0.12%—IBM DB2 Mirror FOR IAI14/9/202616/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.
AnalizadaBaja (3.3)0.15%—IBM DB2 Mirror FOR I4/9/202610/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
AnalizadaMedia (5.3)0.36%—IBM DB2 Mirror FOR I4/9/202610/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
AnalizadaMedia (4.7)0.07%—IBM DB2 Mirror FOR I4/9/20268/9/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
AnalizadaAlta (7.5)0.85%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
AnalizadaAlta (8.1)0.54%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
AnalizadaMedia (6.5)0.35%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
AnalizadaMedia (5.4)0.36%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
AnalizadaCrítica (9.8)0.50%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
AnalizadaCrítica (9.8)0.80%—IBM DB2 Mirror FOR I14/8/202621/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
AnalizadaCrítica (9.8)0.73%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
AnalizadaAlta (8.6)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
AnalizadaMedia (6.5)3.1%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
AnalizadaAlta (7.5)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
AnalizadaMedia (6.5)0.52%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
AnalizadaMedia (6.5)0.66%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
AnalizadaAlta (7.5)0.55%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
AnalizadaMedia (4.3)0.32%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
AnalizadaAlta (7.5)0.85%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
AnalizadaMedia (6.5)0.46%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
AnalizadaAlta (8.8)0.50%—IBM DB2 Mirror FOR I14/8/202620/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
AnalizadaAlta (7.5)0.24%—IBM DB2 Mirror FOR I14/8/202626/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
AnalizadaCrítica (9.8)0.86%—IBM DB2 Mirror FOR I12/8/202613/8/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
AnalizadaMedia (6.3)0.19%—IBM DB2 Mirror FOR I23/7/202517/6/2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.