Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.24% | — | Hitachienergy Asset SuiteAI | 30/5/2025 | 17/6/2026 | A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will cause JavaScript code supplied by the attacker to… | |
| Aplazada | Media (4.3) | 0.23% | — | Hitachi OPS Center AnalyzerAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.4-00. | |
| Aplazada | Media (6.5) | 0.27% | — | Hitachi OPS Center Analyzer ViewpointAI | 16/5/2025 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00. | |
| Aplazada | Media (5.4) | 0.14% | — | Hitachi OPS Center AnalyzerAI | 16/5/2025 | 17/6/2026 | Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-00. | |
| Aplazada | Media (6.5) | 0.17% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 16/5/2025 | 17/6/2026 | Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before… | |
| Aplazada | Baja (3.9) | 0.14% | — | Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Aplazada | Media (5.3) | 0.16% | — | Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Aplazada | Alta (8.7) | 0.38% | — | Hitachi JP1 IT Desktop Management 2 Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Aplazada | Media (5.5) | 0.17% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center Analyzer Viewpoint OVFAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 11.0.0-04. | |
| Aplazada | Media (4.9) | 0.44% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (4.9) | 0.42% | — | Hitachivantara Pentaho Business Analytics ServerAIHitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (4.4) | 0.29% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a… | |
| Aplazada | Media (6.8) | 0.49% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Media (6.8) | 0.43% | — | Hitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Media (6.1) | 0.15% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans… | |
| Aplazada | Media (4.4) | 0.29% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a… | |
| Aplazada | Crítica (9.1) | 0.94% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Description Hitachi Vantara Pentaho Data Integration & Analytics versions before… | |
| Aplazada | Media (6.5) | 0.33% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280) Hitachi Vantara Pentaho Business Analytics Server… | |
| Aplazada | Media (4.9) | 0.37% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows… | |
| Aplazada | Media (6.5) | 0.33% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.… | |
| Aplazada | Media (6.3) | 0.29% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 20/2/2025 | 17/6/2026 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and… | |
| Aplazada | Alta (8.8) | 0.72% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 19/2/2025 | 17/6/2026 | The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9,… | |
| Aplazada | Alta (8.8) | 0.49% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9,… |