Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

383 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.4)0.28%—Hitachivantara Pentaho Business Analytics ServerAI19/2/202517/6/2026
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)…
AplazadaAlta (8.6)0.52%—Hitachivantara Pentaho Business Analytics ServerAI19/2/202517/6/2026
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including…
AplazadaCrítica (9.4)0.78%—Hitachi OPS Center AnalyzerAIHitachi Infrastructure Analytics AdvisorAI17/12/202417/6/2026
Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00;…
AplazadaAlta (7.1)0.30%—Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI3/12/202417/6/2026
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.
AnalizadaBaja (2.7)0.37%—Hitachienergy Tro610 FirmwareHitachienergy Tro620 FirmwareHitachienergy Tro670 Firmware29/10/202417/6/2026
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.
ModificadaAlta (7.2)1.6%—Hitachienergy Tro610 FirmwareHitachienergy Tro620 FirmwareHitachienergy Tro670 Firmware29/10/202417/6/2026
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.
AplazadaAlta (8.5)0.27%—Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI12/9/202417/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
AnalizadaMedia (4.3)0.34%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
AnalizadaCrítica (9.8)0.58%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
The product exposes a service that is intended for local only to all network interfaces without any authentication.
AnalizadaAlta (8.8)0.50%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
AnalizadaAlta (8.2)0.22%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
AnalizadaAlta (8.8)0.61%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
AnalizadaAlta (7.8)0.20%—Hitachi OPS Center Common Services27/8/202417/6/2026
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.
AplazadaMedia (6.7)0.17%—Hitachi Device ManagerAI6/8/202417/6/2026
Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.
AnalizadaCrítica (9.8)0.36%—Hitachi Tuning Manager6/8/202417/6/2026
Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.
AplazadaAlta (7.8)0.17%—Hitachi JP1 Extensible Snmp AgentAIHitachi JOB Management Partner1 Extensible Snmp AgentAI2/7/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issue affects JP1/Extensible SNMP Agent for Windows: from 12-00 before 12-00-01,…
AnalizadaMedia (6.5)0.20%—Hitachi OPS Center Common Services2/7/202417/6/2026
Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.
ModificadaMedia (6.1)0.25%—Hitachi Pentaho Business Analytics Server26/6/202417/6/2026
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
AnalizadaMedia (6.1)0.29%—Hitachi Pentaho Business Analytics Server26/6/202417/6/2026
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
ModificadaAlta (8.2)0.38%—Hitachi Pentaho Business Analytics Server26/6/202417/6/2026
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
AplazadaMedia (4.4)0.14%—Hitachi Storage Provider FOR Vmware VcenterAI25/6/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
ModificadaMedia (4.1)0.11%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.
AnalizadaMedia (6.5)0.36%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.
ModificadaAlta (8)0.37%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information through complex routines to extend access on the server and other services.
ModificadaCrítica (10)0.68%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.
Orbitaley — Vulnerabilidades