Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+7 | 30/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management for IT and Maximo… | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Smartcloud Control DeskIBM Maximo Industry Solutions | 29/7/2014 | 17/6/2026 | CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+8 | 18/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014,… | |
| Modificada | Media (6.8) | 31% | — | Microsoft Windows Essentials | 15/5/2013 | 16/6/2026 | Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability." | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Smartcloud Control Desk | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Smartcloud Control Desk | 20/2/2013 | 16/6/2026 | IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Smartcloud Control Desk | 20/2/2013 | 16/6/2026 | IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR IT+1 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and… | |
| Modificada | Media (6.2) | 0.29% | — | Webroot Internet Security Essentials | 25/8/2012 | 16/6/2026 | Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Media (6.4) | 1.9% | — | Emerson DeltavEmerson Deltav Proessentials Scientific GraphEmerson Deltav Workstation | 8/6/2012 | 16/6/2026 | An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to overwrite arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 4.0% | — | Emerson DeltavEmerson Deltav Proessentials Scientific GraphEmerson Deltav Workstation | 8/6/2012 | 16/6/2026 | Buffer overflow in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via an invalid field in a project file. | |
| Modificada | Media (5) | 1.9% | — | Emerson DeltavEmerson Deltav Proessentials Scientific GraphEmerson Deltav Workstation | 8/6/2012 | 16/6/2026 | PORTSERV.exe in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) TCP or (2) UDP packet to port 111. | |
| Modificada | Alta (7.5) | 1.5% | — | Emerson DeltavEmerson Deltav Proessentials Scientific GraphEmerson Deltav Workstation | 8/6/2012 | 16/6/2026 | SQL injection vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Emerson DeltavEmerson Deltav Proessentials Scientific GraphEmerson Deltav Workstation | 8/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+30 | 21/3/2012 | 16/6/2026 | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424,… | |
| Modificada | Media (4.3) | 98% | — | Aladdin EsafeAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+24 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus… | |
| Modificada | Media (4.3) | 98% | — | Antiy AVL SDKCA Etrust VET AntivirusDrweb Dr.web AntivirusEmsisoft Anti-malware+10 | 21/3/2012 | 16/6/2026 | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7,… | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAladdin EsafeAlwil Avast AntivirusAnti-virus Vba32+31 | 21/3/2012 | 16/6/2026 | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools… | |
| Modificada | Media (4.3) | 97% | — | Authentium Command AntivirusCAT Quick HealEset Nod32 AntivirusF-prot Antivirus+7 | 21/3/2012 | 16/6/2026 | The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12,… | |
| Modificada | Media (4.3) | 1.9% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/. |