Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.34% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 13/5/2026 | 7/10/2026 | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator. | |
| Analizada | Media (5.3) | 0.30% | — | Hitachi VSP E1090h FirmwareHitachi VSP E790h FirmwareHitachi VSP E590h FirmwareHitachi VSP E390h Firmware+16 | 7/5/2026 | 17/6/2026 | Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block… | |
| Analizada | Crítica (9.8) | 0.55% | — | Hitachi Virtual Storage ONE BlockHitachi VSP G130 FirmwareHitachi VSP G150 FirmwareHitachi VSP G350 Firmware+16 | 7/5/2026 | 17/6/2026 | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One… | |
| Analizada | Crítica (9.8) | 0.90% | — | Hitachi Virtual Storage ONE Block | 7/5/2026 | 17/6/2026 | OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. | |
| Analizada | Media (5.5) | 0.14% | — | Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+1 | 7/4/2026 | 17/6/2026 | Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -… | |
| Analizada | Crítica (9.8) | 0.61% | — | Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+1 | 7/4/2026 | 17/6/2026 | Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -… | |
| Analizada | Media (6.1) | 0.16% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 25/3/2026 | 12/8/2026 | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| En análisis | Media (4.3) | 0.18% | — | Hitachi OPS Center Administrator | 25/3/2026 | 12/8/2026 | Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8. | |
| Analizada | Crítica (9.1) | 0.39% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 10/3/2026 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE. | |
| Analizada | Alta (7.5) | 0.16% | — | Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00. | |
| Analizada | Media (5.2) | 0.14% | 💥 PoC | Hitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before… | |
| Analizada | Alta (7.6) | 0.29% | — | Hitachienergy Reb500 Firmware | 24/2/2026 | 17/6/2026 | A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so. | |
| Analizada | Alta (7.4) | 0.34% | — | Hitachienergy Reb500 Firmware | 24/2/2026 | 17/6/2026 | A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so. | |
| Modificada | Alta (8.7) | 0.42% | — | Hitachienergy Rtu540 FirmwareHitachienergy Rtu560 FirmwareHitachienergy Rtu520 FirmwareHitachienergy Rtu530 Firmware | 24/2/2026 | 17/6/2026 | IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of… | |
| Analizada | Media (5.3) | 0.27% | — | Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware | 24/2/2026 | 17/6/2026 | RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges. | |
| Aplazada | Alta (7.1) | 0.22% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Alta (8.2) | 0.20% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Media (5.3) | 0.29% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI | 15/12/2025 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | |
| Aplazada | Media (6) | 0.29% | — | Hitachienergy Asset SuiteAI | 30/9/2025 | 17/6/2026 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application… | |
| Analizada | Alta (7.1) | 0.20% | — | Hitachienergy Microscada X Sys600 | 24/6/2025 | 17/6/2026 | A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation. | |
| Analizada | Alta (8.5) | 0.36% | — | Hitachienergy Microscada X Sys600 | 24/6/2025 | 17/6/2026 | A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user. | |
| Analizada | Alta (7.1) | 0.22% | — | Hitachienergy Microscada X Sys600 | 24/6/2025 | 17/6/2026 | A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop. | |
| Analizada | Alta (8.3) | 0.23% | — | Hitachienergy Microscada X Sys600 | 24/6/2025 | 17/6/2026 | A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption. | |
| Analizada | Media (6.9) | 0.13% | — | Hitachienergy Microscada X Sys600 | 24/6/2025 | 17/6/2026 | A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service. | |
| Aplazada | Crítica (9.1) | 0.38% | — | Hitachienergy Asset SuiteAI | 30/5/2025 | 17/6/2026 | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded. |