Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.39% | — | IBM Verify Identity AccessAI | 15/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Pendiente de análisis | Alta (7.2) | 0.32% | — | IBM Verify Identity AccessAI | 15/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | IBM Security Verify Identity Access Reverse ProxyAI | 15/9/2026 | 16/9/2026 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Pendiente de análisis | Crítica (9.8) | 0.29% | — | IBM Verify Identity AccessAI | 15/9/2026 | 17/9/2026 | IBM Verify Identity Access is vulnerable to a buffer overflow attack. | |
| Pendiente de análisis | Alta (7.5) | 0.31% | — | IBM Verify Identity AccessAI | 15/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | IBM Verify Identity AccessAI | 15/9/2026 | 17/9/2026 | IBM Verify Identity Access containers may not apply management password change operations correctly. | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | IBM Verify Identity AccessAI | 15/9/2026 | 19/9/2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests. | |
| Pendiente de análisis | Media (6.5) | 0.17% | — | IBM Security Verify Identity AccessAI | 15/9/2026 | 19/9/2026 | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. | |
| Pendiente de análisis | Media (4.7) | 0.28% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001. | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Pendiente de análisis | Media (5.4) | 0.15% | — | IBM Verify Identity AccessAI | 14/9/2026 | 19/9/2026 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems. | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | IBM Verify Identity Access Advanced Access ControlAI | 4/9/2026 | 8/9/2026 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 18/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. | |
| Analizada | Alta (8.1) | 0.35% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a… | |
| Analizada | Alta (8.7) | 0.49% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by… | |
| Analizada | Baja (3.1) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |
| Analizada | Alta (7.4) | 0.32% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Media (5.3) | 0.40% | — | IBM Verify Identity AccessIBM Verify Identity Access Container | 30/7/2026 | 12/8/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 17/7/2026 | 11/8/2026 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (6.1) | 0.36% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 17/7/2026 | 30/7/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect… |