Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 2/3/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… | |
| Modificada | Media (5.5) | 0.19% | — | IBM Maximo Application Suite | 24/2/2023 | 17/6/2026 | IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584. | |
| Modificada | Alta (7.5) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 17/2/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587. | |
| Modificada | Alta (8.8) | 0.51% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 9/1/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335. | |
| Modificada | Media (5.5) | 0.17% | — | IBM Maximo Application Suite | 28/11/2022 | 17/6/2026 | IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 14/9/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163. | |
| Modificada | Alta (7.2) | 1.1% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 3/5/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 30/8/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 27/8/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694. |