Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Baja (3.7) | 0.26% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. | |
| Analizada | Media (5.3) | 0.16% | — | IBM Websphere Application Server | 18/9/2026 | 24/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. | |
| Pendiente de análisis | Media (4.3) | 0.18% | — | IBM Websphere Application ServerAI | 18/9/2026 | 19/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | |
| En análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 30/9/2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. | |
| Pendiente de análisis | Media (5.9) | 0.31% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. | |
| Pendiente de análisis | Baja (3.1) | 0.16% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | |
| Pendiente de análisis | Media (4.8) | 0.22% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | |
| Pendiente de análisis | Media (6.4) | 0.20% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Analizada | Media (5.3) | 0.43% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |
| Analizada | Alta (8.1) | 0.37% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |
| Analizada | Alta (7.1) | 0.16% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. |