Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.32% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the… | |
| Analizada | Media (5.3) | 0.32% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system. |