Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow. | |
| Analizada | Media (4.3) | 0.37% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (6.5) | 0.36% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security. | |
| Analizada | Media (4.3) | 0.27% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.7) | 0.41% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (6.4) | 0.26% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.3) | 0.43% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling. | |
| Modificada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (5.3) | 0.17% | — | IBM Watsonx.data | 26/5/2026 | 24/7/2026 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions. | |
| En análisis | Media (5.5) | 0.09% | — | IBM Watsonx.data | 30/4/2026 | 30/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM Watsonx.data | 30/4/2026 | 30/9/2026 | IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions. | |
| Analizada | Baja (2.7) | 0.19% | — | IBM Watsonx.data | 17/2/2026 | 17/6/2026 | IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data. | |
| Analizada | Media (6.5) | 0.29% | — | IBM Watsonx.data | 8/12/2025 | 17/6/2026 | IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits. | |
| Analizada | Media (5.5) | 0.12% | — | IBM Watsonx.data | 27/9/2025 | 17/6/2026 | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Media (4.3) | 0.23% | — | IBM Watsonx.data | 18/9/2025 | 17/6/2026 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system. | |
| Analizada | Alta (7.2) | 0.34% | — | IBM Watsonx.data | 18/9/2025 | 17/6/2026 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input. | |
| Analizada | Media (4.8) | 0.19% | — | IBM Watsonx.data | 18/9/2025 | 17/6/2026 | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |