Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

403 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)86%💥 ExploitRedhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+119/11/201717/6/2026
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat…
ModificadaMedia (6.1)0.75%—Redhat Subscription Asset Manager16/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaMedia (5.5)0.80%—IBM Maximo Asset Management12/9/201717/6/2026
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
ModificadaAlta (8.8)11%—Manageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It36028/8/201717/6/2026
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.
ModificadaAlta (8.8)78%💥 ExploitManageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It36028/8/201717/6/2026
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
ModificadaMedia (4.3)0.91%—IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials9/8/201717/6/2026
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
ModificadaCrítica (9.8)1.2%—Quest Kace Asset Management ApplianceQuest Kace Systems Management ApplianceQuest K1000 AS A Service7/8/201717/6/2026
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
ModificadaMedia (6.3)0.73%—Hammock Assetview17/7/201717/6/2026
SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".
ModificadaMedia (6.5)1.6%—Hammock Assetview17/7/201717/6/2026
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service".
ModificadaMedia (5.4)0.73%—IBM Maximo Asset Management5/7/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
ModificadaBaja (3.3)0.32%—IBM Maximo Asset Management5/7/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.
ModificadaCrítica (9.8)1.9%—IBM Maximo Asset Management5/7/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
ModificadaAlta (8.8)1.6%—IBM Maximo Asset Management13/6/201717/6/2026
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
ModificadaMedia (4.3)0.96%—IBM Maximo Asset Management8/6/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
ModificadaAlta (8.8)1.8%—IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials7/6/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
ModificadaMedia (5.3)0.86%—IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials26/5/201717/6/2026
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.
ModificadaMedia (5.4)0.61%—IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials26/5/201717/6/2026
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache…
ModificadaMedia (5.4)0.95%💥 ExploitInfor Enterprise Asset Management16/5/201717/6/2026
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
ModificadaAlta (8.8)1.4%💥 ExploitInfor Enterprise Asset Management16/5/201717/6/2026
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
ModificadaAlta (8.4)1.7%—IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials3/5/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
ModificadaMedia (6.1)1.2%—Uchida Assetbase28/4/201717/6/2026
Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.6)0.78%—IBM Maximo Asset Management26/4/201717/6/2026
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
ModificadaMedia (6.5)6.0%💥 ExploitIBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+724/4/201717/6/2026
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users…
ModificadaAlta (8.8)6.8%💥 ExploitIBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+724/4/201717/6/2026
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users…
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.