Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.81%—Siemens Cerberus PRO EN Engineering ToolSiemens Cerberus PRO EN Fire Panel Fc72xSiemens Cerberus PRO EN X200 Cloud DistributionSiemens Cerberus PRO EN X300 Cloud Distribution+512/3/202417/6/2026
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions < V3.0.6602), Cerberus PRO EN X200 Cloud…
AplazadaMedia (4.3)0.33%—Hcengineering Huly PlatformAI7/3/202417/6/2026
Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.
AnalizadaMedia (5.4)0.30%—IBM Engineering Test Management3/3/202417/6/2026
IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267459.
ModificadaMedia (5.1)0.20%—IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access1/3/202417/6/2026
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.
ModificadaMedia (6.5)0.25%—IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access1/3/202417/6/2026
IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216.
ModificadaMedia (4.8)0.32%—IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access1/3/202417/6/2026
IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251052.
ModificadaAlta (7.5)0.66%—IBM Engineering Lifecycle Optimization9/2/202417/6/2026
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.
ModificadaMedia (6.1)0.26%—IBM Engineering Lifecycle Optimization9/2/202417/6/2026
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM…
ModificadaAlta (8.8)0.38%—IBM Engineering Lifecycle Optimization9/2/202417/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749.
ModificadaMedia (5.5)0.19%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle Management6/10/202317/6/2026
IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498.
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component.
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component.
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component.
ModificadaAlta (7.5)0.57%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.66%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.60%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
ModificadaMedia (5.5)0.23%—ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware22/5/202317/6/2026
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to…
ModificadaAlta (8.8)1.6%—Aspiresoftware Open Aviation Strategic Engineering System16/9/202217/6/2026
OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu.
ModificadaMedia (5.4)0.47%—IBM Engineering Test ManagementIBM Rational Quality Manager29/8/202217/6/2026
IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210671.
ModificadaCrítica (9.8)1.0%—Generalized Electric Vehicle Reverse Engineering Tool Project Generalized Electric Vehicle Reverse Engineering Tool3/8/202217/6/2026
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
ModificadaMedia (6.5)0.37%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
ModificadaMedia (6.5)0.86%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738.
ModificadaMedia (5.4)0.50%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…