Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.28% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)… | |
| Aplazada | Alta (8.6) | 0.52% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including… | |
| Aplazada | Crítica (9.4) | 0.78% | — | Hitachi OPS Center AnalyzerAIHitachi Infrastructure Analytics AdvisorAI | 17/12/2024 | 17/6/2026 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00;… | |
| Aplazada | Alta (7.1) | 0.30% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 3/12/2024 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01. | |
| Analizada | Baja (2.7) | 0.37% | — | Hitachienergy Tro610 FirmwareHitachienergy Tro620 FirmwareHitachienergy Tro670 Firmware | 29/10/2024 | 17/6/2026 | Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access. | |
| Modificada | Alta (7.2) | 1.6% | — | Hitachienergy Tro610 FirmwareHitachienergy Tro620 FirmwareHitachienergy Tro670 Firmware | 29/10/2024 | 17/6/2026 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends. | |
| Aplazada | Alta (8.5) | 0.27% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI | 12/9/2024 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. | |
| Analizada | Media (4.3) | 0.34% | — | Hitachienergy Microscada X Sys600 | 27/8/2024 | 17/6/2026 | An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. | |
| Analizada | Crítica (9.8) | 0.58% | — | Hitachienergy Microscada X Sys600 | 27/8/2024 | 17/6/2026 | The product exposes a service that is intended for local only to all network interfaces without any authentication. | |
| Analizada | Alta (8.8) | 0.50% | — | Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys600 | 27/8/2024 | 17/6/2026 | A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential. | |
| Analizada | Alta (8.2) | 0.22% | — | Hitachienergy Microscada X Sys600 | 27/8/2024 | 17/6/2026 | An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it. | |
| Analizada | Alta (8.8) | 0.61% | — | Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys600 | 27/8/2024 | 17/6/2026 | The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application. | |
| Analizada | Alta (7.8) | 0.20% | — | Hitachi OPS Center Common Services | 27/8/2024 | 17/6/2026 | Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01. | |
| Aplazada | Media (6.7) | 0.17% | — | Hitachi Device ManagerAI | 6/8/2024 | 17/6/2026 | Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00. | |
| Analizada | Crítica (9.8) | 0.36% | — | Hitachi Tuning Manager | 6/8/2024 | 17/6/2026 | Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00. | |
| Aplazada | Alta (7.8) | 0.17% | — | Hitachi JP1 Extensible Snmp AgentAIHitachi JOB Management Partner1 Extensible Snmp AgentAI | 2/7/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issue affects JP1/Extensible SNMP Agent for Windows: from 12-00 before 12-00-01,… | |
| Analizada | Media (6.5) | 0.20% | — | Hitachi OPS Center Common Services | 2/7/2024 | 17/6/2026 | Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00. | |
| Modificada | Media (6.1) | 0.25% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface. | |
| Analizada | Media (6.1) | 0.29% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface. | |
| Modificada | Alta (8.2) | 0.38% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. | |
| Aplazada | Media (4.4) | 0.14% | — | Hitachi Storage Provider FOR Vmware VcenterAI | 25/6/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4. | |
| Modificada | Media (4.1) | 0.11% | — | Hitachienergy Foxman-unHitachienergy Unem | 11/6/2024 | 17/6/2026 | A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere. | |
| Analizada | Media (6.5) | 0.36% | — | Hitachienergy Foxman-unHitachienergy Unem | 11/6/2024 | 17/6/2026 | A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account. | |
| Modificada | Alta (8) | 0.37% | — | Hitachienergy Foxman-unHitachienergy Unem | 11/6/2024 | 17/6/2026 | A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information through complex routines to extend access on the server and other services. | |
| Modificada | Crítica (10) | 0.68% | — | Hitachienergy Foxman-unHitachienergy Unem | 11/6/2024 | 17/6/2026 | An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface. |