Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.14% | — | IBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) FirmwareIBM Power System S914 (9009-41g) FirmwareIBM Power System S924 (9009-42g) Firmware+6 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service… | |
| Analizada | Alta (8.1) | 0.15% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the BMC/FSP can… | |
| Analizada | Alta (8.2) | 0.17% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+25 | 19/8/2026 | 25/8/2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP… | |
| Analizada | Crítica (9.8) | 0.76% | — | IBM Hardware Management Console | 30/7/2026 | 10/8/2026 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Hardware Management Console | 9/9/2025 | 17/6/2026 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Hardware Management Console R10.0 FirmwareIBM Hardware Management Console R9.4 FirmwareIBM Hardware Management Console R9.3 Firmware | 27/5/2025 | 17/6/2026 | IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.7) | 0.22% | — | IBM Hardware Management Console | 22/4/2025 | 17/6/2026 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM Hardware Management Console | 22/4/2025 | 17/6/2026 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source. | |
| Analizada | Media (6.5) | 0.51% | — | IBM Power Hardware Management Console | 14/2/2025 | 17/6/2026 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Hardware Management Console | 16/10/2023 | 17/6/2026 | IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740. | |
| Modificada | Media (4.9) | 0.45% | — | IBM Power System Ac922 (8335-gtg) FirmwareIBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Hardware Management Console 7063-cr2 Firmware | 22/8/2022 | 17/6/2026 | IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Power Hardware Management Console (7063-cr2) Firmware | 4/2/2022 | 17/6/2026 | IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047. | |
| Modificada | Media (5.9) | 0.99% | — | IBM Power Hardware Management Console (7063-cr1) FirmwareIBM Power System Cs822lc (8005-22n) FirmwareIBM Power System Cs821lc (8005-12n) FirmwareIBM Power System S822lc (8001-22c) Firmware+1 | 15/12/2021 | 17/6/2026 | BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267. | |
| Modificada | Alta (7.8) | 0.30% | — | IBM Hardware Management Console | 19/7/2021 | 17/6/2026 | IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879. | |
| Modificada | Media (6.1) | 0.64% | — | IBM Power Hardware Management Console | 20/4/2018 | 17/6/2026 | IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163. | |
| Modificada | Media (4.6) | 0.47% | — | Kernel Util-linuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+5 | 11/4/2017 | 17/6/2026 | The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset. | |
| Modificada | Alta (7.8) | 0.34% | — | IBM Power Hardware Management Console | 20/3/2017 | 17/6/2026 | IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459. | |
| Modificada | Media (6.8) | 0.44% | — | IBM Hardware Management Console | 7/7/2016 | 17/6/2026 | IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | IBM Power Hardware Management Console | 17/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.35% | — | IBM Power Hardware Management Console FirmwareIBM Systems Director Management Console Firmware | 6/8/2012 | 16/6/2026 | IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a… | |
| Modificada | Alta (9.3) | 1.3% | — | IBM Hardware Management Console | 28/5/2009 | 16/6/2026 | Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are… | |
| Modificada | Alta (10) | 1.8% | — | IBM Hardware Management Console | 20/1/2009 | 16/6/2026 | Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Hardware Management Console | 10/11/2008 | 16/6/2026 | The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length. |