Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 18/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system. | |
| Pendiente de análisis | Media (5.9) | 0.17% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 21/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. | |
| Pendiente de análisis | Media (5.9) | 0.17% | — | IBM Cognos AnalyticsAI | 18/9/2026 | 28/9/2026 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | IBM Cognos AnalyticsAI | 14/9/2026 | 16/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code… | |
| Analizada | Media (4.2) | 0.17% | — | IBM Cognos Analytics | 17/7/2026 | 11/8/2026 | IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit… | |
| Analizada | Alta (8.2) | 0.31% | — | IBM Cognos AnalyticsIBM Cognos Transformer | 27/5/2026 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead… | |
| Analizada | Alta (7.6) | 0.18% | — | IBM Cognos AnalyticsIBM Cognos Transformer | 26/5/2026 | 24/7/2026 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… | |
| Analizada | Media (5.3) | 0.23% | — | IBM Cognos Analytics Certified Containers | 10/11/2025 | 17/6/2026 | IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages. | |
| Analizada | Alta (8.2) | 0.19% | — | IBM Cognos Analytics Mobile | 21/7/2025 | 17/6/2026 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential information on the device or network by using a the deprecated or misconfigured AFNetworking library at runtime. | |
| Analizada | Alta (7.5) | 0.22% | — | IBM Cognos Analytics Mobile | 21/7/2025 | 17/6/2026 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic. | |
| Analizada | Media (4.6) | 0.18% | — | IBM Cognos Analytics Mobile | 21/7/2025 | 17/6/2026 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication is not used in the application. | |
| Analizada | Alta (7.5) | 0.23% | — | IBM Cognos Analytics Mobile | 21/7/2025 | 17/6/2026 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data. | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cognos Analytics | 28/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources. | |
| Analizada | Media (5.3) | 0.28% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system. | |
| Analizada | Media (4.8) | 0.21% | — | IBM Cognos Analytics | 11/6/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Analizada | Baja (2.4) | 0.20% | — | IBM Cognos Analytics Mobile | 2/3/2025 | 17/6/2026 | IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages. | |
| Analizada | Media (5.3) | 0.27% | — | IBM Cognos Analytics Mobile | 2/3/2025 | 17/6/2026 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation. | |
| Analizada | Media (6.5) | 0.60% | — | IBM Cognos Analytics | 28/2/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Modificada | Media (6.5) | 0.84% | — | IBM Cognos Analytics | 28/2/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter. | |
| Analizada | Alta (7.1) | 0.48% | — | IBM Cognos Analytics | 5/2/2025 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Cognos Analytics | 26/1/2025 | 17/6/2026 | IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning. | |
| Analizada | Crítica (9) | 0.59% | — | IBM Cognos Analytics | 20/12/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL… | |
| Analizada | Alta (8) | 0.42% | — | IBM Cognos Analytics | 20/12/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for… | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Cognos Analytics Mobile | 19/12/2024 | 17/6/2026 | IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |