Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.45% | — | Siemens Simatic PCS 7Siemens Simatic Process Device ManagerSiemens Simatic Step 7Siemens Sinamics Starter | 10/6/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A DLL Hijacking… | |
| Modificada | Media (4.9) | 1.2% | — | Cisco Firepower Device Manager On-box | 6/5/2020 | 17/6/2026 | A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow an authenticated, remote attacker to cause an affected system to become unstable or reload. The vulnerability is due to insufficient hardening of the XML parser configuration. An attacker could exploit this… | |
| Modificada | Alta (7.2) | 1.8% | — | Cisco Firepower Device Manager On-box | 6/5/2020 | 17/6/2026 | A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by uploading a… | |
| Modificada | Media (6.5) | 0.84% | — | Hitachi Device ManagerHitachi Compute Systems ManagerHitachi Automation DirectorHitachi Tiered Storage Manager+4 | 14/2/2020 | 17/6/2026 | A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device… | |
| Modificada | Media (4.3) | 0.87% | — | Hitachi Device ManagerHitachi Compute Systems ManagerHitachi Automation Director | 14/2/2020 | 17/6/2026 | A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager. | |
| Modificada | Alta (7.5) | 1.3% | — | Hitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage ManagerHitachi Infrastructure Analytics Advisor+1 | 12/11/2019 | 17/6/2026 | A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 1.4% | — | Hitachi Device ManagerHitachi Tiered Storage ManagerHitachi Replication ManagerHitachi Tuning Manager+1 | 12/11/2019 | 17/6/2026 | A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information. | |
| Modificada | Media (6.5) | 1.6% | — | HP XP7 Device ManagerHP XP7 Replication ManagerHP XP7 Tiered Storage Manager | 9/8/2019 | 17/6/2026 | Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier… | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Adaptive Security Appliance Device ManagerCisco Secure Firewall Threat Defense | 3/5/2019 | 11/8/2026 | A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling… | |
| Modificada | Alta (7.8) | 0.28% | — | Puppet Device Manager | 2/10/2018 | 17/6/2026 | Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0. | |
| Modificada | Media (6.5) | 0.90% | — | Emerson AMS Device Manager | 1/10/2018 | 17/6/2026 | Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products. | |
| Modificada | Crítica (9.8) | 3.5% | — | Emerson AMS Device Manager | 1/10/2018 | 17/6/2026 | Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution. | |
| Modificada | Alta (7.5) | 2.4% | — | HP XP P9000 Configuration ManagerHP XP P9000 Device Manager | 14/8/2018 | 17/6/2026 | A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Hitachi Compute Systems ManagerHitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage Manager+2 | 9/8/2018 | 17/6/2026 | An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message. | |
| Modificada | Alta (7.5) | 2.2% | — | Alcatel-lucent Home Device Manager | 9/8/2017 | 17/6/2026 | Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices. | |
| Modificada | Media (5.4) | 0.61% | — | Hitachi Device Manager | 29/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code. | |
| Modificada | Media (6.1) | 0.93% | — | Hitachi Device Manager | 29/5/2017 | 17/6/2026 | Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites. | |
| Modificada | Media (6.1) | 0.93% | — | Hitachi Device Manager | 29/5/2017 | 17/6/2026 | Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites. | |
| Modificada | Media (6.5) | 1.1% | — | Hitachi Device Manager | 29/5/2017 | 17/6/2026 | XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files. | |
| Modificada | Crítica (9.8) | 2.4% | — | Hitachi Device Manager | 29/5/2017 | 17/6/2026 | RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports. | |
| Modificada | Media (5.4) | 0.64% | — | Alcatel-lucent Motive Home Device Manager | 23/3/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Intrusion Prevention System Device Manager | 22/2/2017 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7. | |
| Modificada | Media (6.5) | 1.3% | — | Emerson AMS Device Manager | 26/5/2015 | 17/6/2026 | SQL injection vulnerability in Emerson AMS Device Manager before 13 allows remote authenticated users to gain privileges via malformed input. | |
| Modificada | Media (4.3) | 2.5% | — | HP XP P9000 Device ManagerHP XP P9000 Replication ManagerHP XP P9000 Tiered Storage ManagerHP XP7 Global Link Manager Software | 3/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP… |