Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.8% | — | IBM Maximo Asset Management | 13/9/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967. | |
| Modificada | Alta (8.8) | 1.7% | — | IBM Maximo Asset Management | 24/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145968. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Maximo Asset Management | 16/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+4 | 6/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+4 | 3/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Maximo Asset Management | 2/8/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142891. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy OptimizationIBM Maximo FOR Aviation+10 | 27/3/2018 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via… | |
| Modificada | Media (5.4) | 0.73% | — | IBM Maximo Asset Management | 22/2/2018 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821. | |
| Modificada | Alta (8.8) | 1.5% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 22/2/2018 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820. | |
| Modificada | Alta (8.8) | 2.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 14/2/2018 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106. | |
| Modificada | Media (6.1) | 0.99% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/12/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that… | |
| Modificada | Media (5.5) | 0.80% | — | IBM Maximo Asset Management | 12/9/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. | |
| Modificada | Media (4.3) | 0.91% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 9/8/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quest Kace Asset Management ApplianceQuest Kace Systems Management ApplianceQuest K1000 AS A Service | 7/8/2017 | 17/6/2026 | SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. | |
| Modificada | Baja (3.3) | 0.32% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. | |
| Modificada | Crítica (9.8) | 1.9% | — | IBM Maximo Asset Management | 5/7/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297. | |
| Modificada | Alta (8.8) | 1.6% | — | IBM Maximo Asset Management | 13/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Maximo Asset Management | 8/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 7/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. | |
| Modificada | Media (5.3) | 0.86% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 26/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153. | |
| Modificada | Media (5.4) | 0.61% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 26/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache… | |
| Modificada | Media (5.4) | 0.95% | 💥 Exploit | Infor Enterprise Asset Management | 16/5/2017 | 17/6/2026 | INFOR EAM V11.0 Build 201410 has XSS via comment fields. | |
| Modificada | Alta (8.8) | 1.4% | 💥 Exploit | Infor Enterprise Asset Management | 16/5/2017 | 17/6/2026 | INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. | |
| Modificada | Alta (8.4) | 1.7% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 3/5/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252. |