Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.54%—IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+81/2/201717/6/2026
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (6.4)0.38%—Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+1415/11/201617/6/2026
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7…
ModificadaCrítica (9.8)4.7%—HP Universal Cmbd FoundationHP Universal Cmbd Configuration ManagerHP Universal Discovery8/6/201617/6/2026
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ModificadaAlta (7.5)9.1%—PerlDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Configuration Manager+68/4/201617/6/2026
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
ModificadaMedia (5.4)0.71%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+912/3/201617/6/2026
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13…
ModificadaMedia (5.3)1.3%—Novell Zenworks Configuration Management18/2/201617/6/2026
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
ModificadaMedia (4.1)0.28%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+927/1/201617/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset…
ModificadaMedia (5)1.8%—Oracle Human Capital Management Configuration Workbench21/1/201617/6/2026
Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors.
ModificadaMedia (5.4)0.66%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+93/1/201617/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset…
ModificadaMedia (6.5)1.5%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+78/11/201517/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset…
ModificadaMedia (4)0.96%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+78/11/201517/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset…
ModificadaMedia (6.5)0.99%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+96/10/201517/6/2026
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2…
ModificadaMedia (4)0.97%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+96/10/201517/6/2026
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1…
ModificadaBaja (3.5)0.78%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+96/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through…
ModificadaMedia (5)0.99%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+94/10/201517/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management…
ModificadaBaja (2.1)0.44%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+94/10/201517/6/2026
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management…
ModificadaMedia (4.9)0.57%—HP Universal Configuration Management Database16/9/201517/6/2026
HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.
ModificadaAlta (8.5)2.5%—Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System3/9/201517/6/2026
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
ModificadaMedia (4.9)0.98%—Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System3/9/201517/6/2026
Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.
ModificadaAlta (10)74%💥 ExploitNovell Zenworks Configuration Management7/6/201517/6/2026
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST…
ModificadaAlta (10)72%💥 ExploitNovell Zenworks Configuration Management7/6/201516/6/2026
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a zenworks-fileupload request with a crafted directory name in the type parameter, in conjunction with a WAR…
ModificadaAlta (10)14%💥 ExploitNovell Zenworks Configuration Management7/6/201516/6/2026
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different…
ModificadaMedia (4.3)2.1%—Fedora Pacemaker Configuration System14/5/201517/6/2026
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability…
ModificadaMedia (6.8)2.4%—Fedora Pacemaker Configuration SystemRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUSRedhat Enterprise Linux Resilient Storage+114/5/201517/6/2026
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types.…
ModificadaAlta (7.5)48%💥 ExploitSolarwinds Orion IP Address ManagerSolarwinds Orion Netflow Traffic AnalyzerSolarwinds Orion Network Configuration ManagerSolarwinds Orion Network Performance Monitor+410/3/201517/6/2026
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager…
Orbitaley — Vulnerabilidades