Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.55%—IBM Maximo Asset Management2/2/202417/6/2026
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.
ModificadaAlta (8.8)0.29%—IBM Maximo Application SuiteIBM Maximo Asset Management19/1/202417/6/2026
IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843.
ModificadaMedia (5.4)0.28%—IBM Maximo Application SuiteIBM Maximo Asset Management19/1/202417/6/2026
IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 255288.
ModificadaMedia (6.1)0.30%—Microfocus Asset Management XMicrofocus Service Management Automation X30/10/202317/6/2026
Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user…
ModificadaAlta (8.8)0.79%—Projectworlds Asset Management System28/9/202317/6/2026
Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
ModificadaCrítica (9.8)0.86%—Projectworlds Asset Management System28/9/202317/6/2026
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
ModificadaCrítica (9.8)1.1%💥 PoCProjectworlds Asset Management System Project IN PHP22/9/202317/6/2026
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
ModificadaMedia (5.4)0.63%—IBM Maximo Application SuiteIBM Maximo Asset Management8/9/202317/6/2026
IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072.
ModificadaMedia (5.3)0.64%—IBM Maximo Application SuiteIBM Maximo Asset Management5/6/202317/6/2026
IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.
ModificadaMedia (5.4)0.37%—IBM Maximo Asset Management5/5/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239436.
ModificadaMedia (5.4)0.48%—IBM Maximo Asset Management28/4/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 249327.
ModificadaMedia (5.3)0.53%—IBM Maximo Asset Management27/4/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.
ModificadaMedia (5.4)0.49%—IBM Maximo Application SuiteIBM Maximo Asset Management2/3/202317/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…
ModificadaAlta (7.5)0.50%—IBM Maximo Application SuiteIBM Maximo Asset Management17/2/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.
ModificadaAlta (8.8)0.51%—IBM Maximo Application SuiteIBM Maximo Asset Management9/1/202317/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.
ModificadaAlta (8.1)0.58%—IBM Maximo Asset Management21/9/202217/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access to. IBM X-Force ID: 236311.
ModificadaAlta (7.5)1.0%—IBM Maximo Application SuiteIBM Maximo Asset Management14/9/202217/6/2026
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
ModificadaCrítica (9.8)1.2%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
ModificadaMedia (5.3)0.77%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request.
ModificadaAlta (7.5)0.96%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request.
ModificadaCrítica (9.8)1.1%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.
ModificadaMedia (5.4)0.47%—IBM Maximo Asset Management26/8/202217/6/2026
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116.
ModificadaAlta (7.2)1.1%—IBM Maximo Application SuiteIBM Maximo Asset Management3/5/202217/6/2026
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct…
ModificadaMedia (5.4)0.48%—IBM Maximo Asset Management21/4/202217/6/2026
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224164.
ModificadaMedia (5.4)0.48%—IBM Maximo Asset Management21/4/202217/6/2026
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Orbitaley — Vulnerabilidades