Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Redhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+11 | 9/11/2017 | 17/6/2026 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat… | |
| Modificada | Media (6.1) | 0.75% | — | Redhat Subscription Asset Manager | 16/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (5.5) | 0.80% | — | IBM Maximo Asset Management | 12/9/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. | |
| Modificada | Alta (8.8) | 11% | — | Manageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It360 | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code. | |
| Modificada | Alta (8.8) | 78% | 💥 Exploit | Manageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It360 | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | |
| Modificada | Media (4.3) | 0.91% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 9/8/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quest Kace Asset Management ApplianceQuest Kace Systems Management ApplianceQuest K1000 AS A Service | 7/8/2017 | 17/6/2026 | SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2. | |
| Modificada | Media (6.3) | 0.73% | — | Hammock Assetview | 17/7/2017 | 17/6/2026 | SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service". | |
| Modificada | Media (6.5) | 1.6% | — | Hammock Assetview | 17/7/2017 | 17/6/2026 | Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service". | |
| Modificada | Media (5.4) | 0.73% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. | |
| Modificada | Baja (3.3) | 0.32% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. | |
| Modificada | Crítica (9.8) | 1.9% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297. | |
| Modificada | Alta (8.8) | 1.6% | — | IBM Maximo Asset Management | 13/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Maximo Asset Management | 8/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 7/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. | |
| Modificada | Media (5.3) | 0.86% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 26/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153. | |
| Modificada | Media (5.4) | 0.61% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 26/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache… | |
| Modificada | Media (5.4) | 0.95% | 💥 Exploit | Infor Enterprise Asset Management | 16/5/2017 | 17/6/2026 | INFOR EAM V11.0 Build 201410 has XSS via comment fields. | |
| Modificada | Alta (8.8) | 1.4% | 💥 Exploit | Infor Enterprise Asset Management | 16/5/2017 | 17/6/2026 | INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. | |
| Modificada | Alta (8.4) | 1.7% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 3/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252. | |
| Modificada | Media (6.1) | 1.2% | — | Uchida Assetbase | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.6) | 0.78% | — | IBM Maximo Asset Management | 26/4/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537. | |
| Modificada | Media (6.5) | 6.0% | 💥 Exploit | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+7 | 24/4/2017 | 17/6/2026 | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users… | |
| Modificada | Alta (8.8) | 6.8% | 💥 Exploit | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+7 | 24/4/2017 | 17/6/2026 | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. |