Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

403 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—IBM Maximo Application SuiteIBM Maximo Asset Management14/9/202217/6/2026
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
ModificadaCrítica (9.8)1.2%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
ModificadaMedia (5.3)0.77%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request.
ModificadaAlta (7.5)0.96%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request.
ModificadaCrítica (9.8)1.1%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.
ModificadaMedia (5.4)0.47%—IBM Maximo Asset Management26/8/202217/6/2026
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116.
ModificadaAlta (7.5)6.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer12/7/202217/6/2026
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
ModificadaCrítica (9.3)1.3%—Iasset Project Iasset11/7/202217/6/2026
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (4.3)1.2%—Silverstripe Assets28/6/202217/6/2026
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
ModificadaCrítica (9.8)2.0%—Pypi Cryptoasset-data-downloader24/6/202217/6/2026
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaAlta (7.2)1.1%—IBM Maximo Application SuiteIBM Maximo Asset Management3/5/202217/6/2026
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct…
ModificadaCrítica (9.8)4.7%—Hammock Assetview28/4/202217/6/2026
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative…
ModificadaMedia (5.4)0.48%—IBM Maximo Asset Management21/4/202217/6/2026
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224164.
ModificadaMedia (5.4)0.48%—IBM Maximo Asset Management21/4/202217/6/2026
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaCrítica (9.8)4.1%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
ModificadaAlta (7.5)1.6%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)5.7%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.9%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.2%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk…
ModificadaMedia (5.4)0.62%—Hitachienergy Ellipse Enterprise Asset Management11/3/202217/6/2026
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential…
ModificadaMedia (6.1)0.57%—Hitachienergy Ellipse Enterprise Asset Management11/3/202217/6/2026
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.
Orbitaley — Vulnerabilidades