Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | — | Apache TomcatDebian LinuxOpensuse LeapCanonical Ubuntu Linux+7 | 23/12/2019 | 17/6/2026 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+5 | 24/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 9/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. | |
| Modificada | Crítica (9.8) | 2.0% | — | Srtalliance Secure Reliable Transport | 29/8/2019 | 17/6/2026 | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections. | |
| Modificada | Crítica (9.8) | 7.3% | — | Axway Securetransport | 26/7/2019 | 17/6/2026 | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant… | |
| Modificada | Alta (8) | 2.6% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. | |
| Modificada | Media (5.4) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949. | |
| Modificada | Media (4.3) | 0.85% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. | |
| Modificada | Media (6.5) | 0.77% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. | |
| Modificada | Media (6.1) | 0.98% | — | Oracle Transportation Management | 23/4/2019 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.3.7, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.9) | 4.1% | 💥 PoC | Digi Transport Lr54 Firmware | 21/3/2019 | 17/6/2026 | Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root. | |
| Modificada | Media (5.9) | 1.5% | — | Etsi Enterprise Transport Security | 26/2/2019 | 17/6/2026 | The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy. | |
| Modificada | Media (6.5) | 1.2% | — | Oracle Transportation Management | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: UI Infrastructure). Supported versions that are affected are 6.3.7, 6.4.1, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (4.3) | 1.3% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+4 | 6/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+4 | 3/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116. | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Transportation Management | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Database). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.… | |
| Modificada | Media (4.3) | 0.97% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy OptimizationIBM Maximo FOR Aviation+10 | 27/3/2018 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via… | |
| Modificada | Media (5.4) | 0.66% | — | Oracle Transportation Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2.11, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7 and 6.4.1. Easily exploitable vulnerability allows low privileged attacker with network access… | |
| Modificada | Media (4.3) | 0.81% | — | Oracle Transportation Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2.11, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.1, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Xi-soft Nettransport Download Manager | 29/12/2017 | 17/6/2026 | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Transportation Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Access Control List). Supported versions that are affected are 6.3.4.1, 6.3.5.1, 6.3.6.1, 6.3.7.1, 6.4.0, 6.4.1 and 6.4.2. Easily exploitable vulnerability allows low privileged attacker with network… | |
| Modificada | Crítica (9.8) | 1.4% | — | Xoev Osci Transport Library | 30/6/2017 | 17/6/2026 | An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from within the infrastructure. |