Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container. | |
| Modificada | Media (5.3) | 0.38% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. | |
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. | |
| Modificada | Media (4.3) | 0.47% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log. | |
| Modificada | Media (4.8) | 0.44% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user. | |
| Modificada | Media (5.5) | 0.17% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack. | |
| Modificada | Media (4.8) | 0.31% | — | Sesami Cash Point & Transport Optimizer | 25/12/2023 | 17/6/2026 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client. | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters. | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Alta (8.8) | 0.62% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation. | |
| Modificada | Media (6.5) | 0.63% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is… | |
| Modificada | Alta (8.8) | 2.2% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system. | |
| Modificada | Alta (8.6) | 0.46% | — | Bentley Assetwise Alim FOR TransportationBentley EB System Management Console | 22/12/2023 | 17/6/2026 | Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before… | |
| Modificada | Alta (8.1) | 0.68% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+16 | 31/8/2023 | 17/6/2026 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | |
| Modificada | Crítica (9.8) | 1.0% | — | Trispark NovuseduTrispark VEO Transportation | 29/8/2023 | 9/7/2026 | TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries. | |
| Modificada | Alta (7.5) | 1.4% | — | Transposh Wordpress Translation | 15/12/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.49% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Media (4.9) | 0.69% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Baja (2.7) | 0.74% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Media (5.4) | 0.56% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.… | |
| Modificada | Media (5.3) | 3.7% | — | Transposh Wordpress Translation | 6/9/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the… |