Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 14/9/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163. | |
| Modificada | Crítica (9.8) | 1.2% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request. | |
| Modificada | Media (5.3) | 0.77% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request. | |
| Modificada | Alta (7.5) | 0.96% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request. | |
| Modificada | Crítica (9.8) | 1.1% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization. | |
| Modificada | Media (5.4) | 0.47% | — | IBM Maximo Asset Management | 26/8/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116. | |
| Modificada | Alta (7.5) | 6.2% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 12/7/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.) | |
| Modificada | Crítica (9.3) | 1.3% | — | Iasset Project Iasset | 11/7/2022 | 17/6/2026 | The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.3) | 1.2% | — | Silverstripe Assets | 28/6/2022 | 17/6/2026 | Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Cryptoasset-data-downloader | 24/6/2022 | 17/6/2026 | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Alta (7.2) | 1.1% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 3/5/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct… | |
| Modificada | Crítica (9.8) | 4.7% | — | Hammock Assetview | 28/4/2022 | 17/6/2026 | Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative… | |
| Modificada | Media (5.4) | 0.48% | — | IBM Maximo Asset Management | 21/4/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224164. | |
| Modificada | Media (5.4) | 0.48% | — | IBM Maximo Asset Management | 21/4/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Crítica (9.8) | 4.1% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. | |
| Modificada | Alta (7.5) | 1.6% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 5.7% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.9% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.2% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk… | |
| Modificada | Media (5.4) | 0.62% | — | Hitachienergy Ellipse Enterprise Asset Management | 11/3/2022 | 17/6/2026 | An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential… | |
| Modificada | Media (6.1) | 0.57% | — | Hitachienergy Ellipse Enterprise Asset Management | 11/3/2022 | 17/6/2026 | An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials. |