Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
9496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.38% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | |
| Analizada | Alta (8.8) | 0.67% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. | |
| En análisis | Crítica (9.1) | 0.68% | — | IBM Guardium Data ProtectionAI | 29/9/2026 | 30/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. | |
| En análisis | Alta (7.2) | 0.68% | — | IBM Guardium Data ProtectionAI | 29/9/2026 | 30/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges. | |
| En análisis | Alta (8.8) | 0.55% | — | IBM DatastageAI | 29/9/2026 | 29/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| En análisis | Alta (7.8) | 0.09% | — | IBM IAI | 29/9/2026 | 30/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path. | |
| Analizada | Alta (7.1) | 0.18% | — | IBM Power System E1080 (9080-hex) FirmwareIBM Power System E1180 (9080-heu) FirmwareIBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) Firmware+5 | 25/9/2026 | 30/9/2026 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to… | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 26/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system. | |
| Pendiente de análisis | Alta (7.2) | 0.37% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system. | |
| Pendiente de análisis | Alta (8.8) | 2.4% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 27/9/2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated… | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Pendiente de análisis | Alta (7.6) | 0.18% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 25/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database. | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | IBM Guardium Data ProtectionAI | 25/9/2026 | 28/9/2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token. | |
| En análisis | Alta (7.1) | 0.28% | — | IBM DatastageAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory. | |
| En análisis | Alta (8.8) | 0.41% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | |
| En análisis | Alta (8.8) | 0.75% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | |
| En análisis | Crítica (9.6) | 0.26% | — | IBM DatastageAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| En análisis | Alta (8.8) | 0.75% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 26/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| En análisis | Alta (8.8) | 0.92% | — | IBM DatastageAIIBM Cloud PAK FOR DataAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | |
| En análisis | Alta (8.8) | 0.85% | — | IBM DatastageAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| En análisis | Alta (8.8) | 0.44% | — | IBM DatastageAI | 24/9/2026 | 24/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Pendiente de análisis | Alta (8.6) | 0.43% | — | IBM Enterprise Build OF QuarkusAI | 24/9/2026 | 24/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Media (4.9) | 0.32% | — | IBM Contextforge | 24/9/2026 | 29/9/2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files… | |
| Analizada | Media (6.2) | 0.12% | — | IBM Concert | 24/9/2026 | 28/9/2026 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface. | |
| Analizada | Baja (3.2) | 0.11% | — | IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+15 | 24/9/2026 | 30/9/2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging… |