Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

383 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.98%—Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server8/11/202117/6/2026
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.
ModificadaAlta (8.8)2.3%—Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server8/11/202117/6/2026
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.
ModificadaAlta (7.8)0.22%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.
ModificadaCrítica (9.8)2.5%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.
ModificadaMedia (6.5)0.82%—Hitachi Content Platform Anywhere29/9/202117/6/2026
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without deleting the link and before the link…
ModificadaAlta (7.8)0.13%—Hitachiabb-powergrids Sdm600 Firmware8/9/202117/6/2026
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).
ModificadaAlta (7.2)1.3%—Hitachienergy Counterparty Settlement AND BillingHitachienergy Retail Operations20/8/202117/6/2026
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids…
ModificadaAlta (7.5)1.0%—Hitachienergy Esoms14/7/202117/6/2026
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.
ModificadaAlta (8.8)3.1%—Hitachi Virtual File PlatformNEC NAS Gateway Nh4a FirmwareNEC NAS Gateway Nh8a FirmwareNEC NAS Gateway Nh4b Firmware+328/6/202117/6/2026
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remote authenticated attackers to execute arbitrary OS commands with…
ModificadaMedia (6.1)0.75%—Hitachi Application Server V10 Manual22/6/202117/6/2026
Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) version 10-11-01 and earlier) allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.51%—Hitachiabb-powergrids Ellipse Asset Performance Management14/6/202117/6/2026
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and…
ModificadaAlta (7.5)1.6%—Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io FirmwareHitachienergy Rtu500 Firmware+514/6/202117/6/2026
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as…
ModificadaAlta (7.5)0.93%—Hitachienergy Esoms14/6/202117/6/2026
Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3.
ModificadaAlta (8.8)0.96%—Hitachi ID Bravura Security Fabric9/6/202117/6/2026
An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating via SAML through a third-party identity provider), an attacker can inject additional data into a signed SAML response being transmitted to the…
ModificadaMedia (5.4)0.62%—Hitachi Vantara Pentaho29/1/202117/6/2026
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'type' attribute of 'dashboardXml' parameter. Remediated in >=…
ModificadaMedia (5.4)0.62%—Hitachi Vantara Pentaho29/1/202117/6/2026
The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section.…
ModificadaMedia (5.4)0.62%—Hitachi Vantara Pentaho29/1/202117/6/2026
The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Display Name' parameter. Remediated in >= 9.1.0.1
ModificadaMedia (6.5)1.1%—Hitachi Vantara Pentaho29/1/202117/6/2026
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lies in the 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >=…
ModificadaMedia (5.4)0.62%—Hitachi Vantara Pentaho29/1/202117/6/2026
The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'pho:title' attribute of 'dashboardXml' parameter. Remediated in >=…
ModificadaCrítica (9.8)71%💥 ExploitHitachienergy Microscada PRO Sys60029/4/202017/6/2026
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
ModificadaAlta (7.5)0.69%—Hitachienergy Esoms2/4/202017/6/2026
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.
ModificadaMedia (6.1)0.29%—Hitachienergy Esoms2/4/202017/6/2026
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
ModificadaMedia (5.4)0.63%—Hitachienergy Esoms2/4/202017/6/2026
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
ModificadaAlta (7.6)0.94%—Hitachienergy Esoms2/4/202017/6/2026
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
ModificadaMedia (6.5)0.85%—Hitachienergy Esoms2/4/202017/6/2026
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.