Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

9496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.38%—IBM Guardium Data Protection29/9/20261/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
AnalizadaAlta (8.8)0.67%—IBM Guardium Data Protection29/9/20261/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
En análisisCrítica (9.1)0.68%—IBM Guardium Data ProtectionAI29/9/202630/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
En análisisAlta (7.2)0.68%—IBM Guardium Data ProtectionAI29/9/202630/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
En análisisAlta (8.8)0.55%—IBM DatastageAI29/9/202629/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
En análisisAlta (7.8)0.09%—IBM IAI29/9/202630/9/2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
AnalizadaAlta (7.1)0.18%—IBM Power System E1080 (9080-hex) FirmwareIBM Power System E1180 (9080-heu) FirmwareIBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) Firmware+525/9/202630/9/2026
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to…
Pendiente de análisisAlta (7.5)0.33%—IBM Guardium Data ProtectionAI25/9/202626/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
Pendiente de análisisAlta (7.2)0.37%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Pendiente de análisisAlta (8.8)2.4%—IBM Guardium Data ProtectionAI25/9/202627/9/2026
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated…
Pendiente de análisisAlta (7.5)0.54%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Pendiente de análisisAlta (7.6)0.18%—IBM Guardium Data ProtectionAI25/9/202625/9/2026
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
Pendiente de análisisAlta (7.5)0.24%—IBM Guardium Data ProtectionAI25/9/202628/9/2026
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
En análisisAlta (7.1)0.28%—IBM DatastageAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
En análisisAlta (8.8)0.41%—IBM DatastageAIIBM Cloud PAK FOR DataAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
En análisisAlta (8.8)0.75%—IBM DatastageAIIBM Cloud PAK FOR DataAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.
En análisisCrítica (9.6)0.26%—IBM DatastageAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
En análisisAlta (8.8)0.75%—IBM DatastageAIIBM Cloud PAK FOR DataAI24/9/202626/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
En análisisAlta (8.8)0.92%—IBM DatastageAIIBM Cloud PAK FOR DataAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
En análisisAlta (8.8)0.85%—IBM DatastageAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
En análisisAlta (8.8)0.44%—IBM DatastageAI24/9/202624/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Pendiente de análisisAlta (8.6)0.43%—IBM Enterprise Build OF QuarkusAI24/9/202624/9/2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AnalizadaMedia (4.9)0.32%—IBM Contextforge24/9/202629/9/2026
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files…
AnalizadaMedia (6.2)0.12%—IBM Concert24/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
AnalizadaBaja (3.2)0.11%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1524/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging…