Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. | |
| Modificada | Media (4.3) | 0.47% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log. | |
| Modificada | Media (4.8) | 0.44% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user. | |
| Modificada | Media (5.5) | 0.17% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack. | |
| Modificada | Media (4.8) | 0.31% | — | Sesami Cash Point & Transport Optimizer | 25/12/2023 | 17/6/2026 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client. | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters. | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Alta (8.8) | 0.62% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation. | |
| Modificada | Media (6.5) | 0.63% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is… | |
| Modificada | Alta (8.8) | 2.2% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system. | |
| Modificada | Alta (8.6) | 0.46% | — | Bentley Assetwise Alim FOR TransportationBentley EB System Management Console | 22/12/2023 | 17/6/2026 | Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before… | |
| Modificada | Alta (8.1) | 0.68% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+16 | 31/8/2023 | 17/6/2026 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Trispark NovuseduTrispark VEO Transportation | 29/8/2023 | 9/7/2026 | TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries. | |
| Modificada | Media (5.4) | 0.49% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Media (4.9) | 0.69% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Baja (2.7) | 0.74% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Media (5.4) | 0.56% | — | Oracle Transportation Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.… | |
| Modificada | Media (6.1) | 0.81% | — | Oracle Transportation Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: User Interface). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management.… | |
| Modificada | Media (6.5) | 1.2% | — | WireWire-ios-transport | 11/3/2022 | 17/6/2026 | Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire… | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Xcom Data Transport | 14/2/2022 | 17/6/2026 | XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges. | |
| Modificada | Alta (7.5) | 0.61% | — | Digi Transport Wr11 FirmwareDigi Transport Wr11 XT FirmwareDigi Transport Wr21 FirmwareDigi Transport Wr31 Firmware+2 | 10/12/2021 | 17/6/2026 | An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session. | |
| Modificada | Alta (8.8) | 0.48% | — | Digi Transport Dr64 FirmwareDigi Transport Vc74 FirmwareDigi Transport Wr11 FirmwareDigi Transport Wr11 XT Firmware+4 | 10/12/2021 | 17/6/2026 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway. |