Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.81% | — | Siemens Cerberus PRO EN Engineering ToolSiemens Cerberus PRO EN Fire Panel Fc72xSiemens Cerberus PRO EN X200 Cloud DistributionSiemens Cerberus PRO EN X300 Cloud Distribution+5 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions < V3.0.6602), Cerberus PRO EN X200 Cloud… | |
| Aplazada | Media (4.3) | 0.33% | — | Hcengineering Huly PlatformAI | 7/3/2024 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file. | |
| Analizada | Media (5.4) | 0.30% | — | IBM Engineering Test Management | 3/3/2024 | 17/6/2026 | IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267459. | |
| Modificada | Media (5.1) | 0.20% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336. | |
| Modificada | Media (6.5) | 0.25% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216. | |
| Modificada | Media (4.8) | 0.32% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 1/3/2024 | 17/6/2026 | IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251052. | |
| Modificada | Alta (7.5) | 0.66% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755. | |
| Modificada | Media (6.1) | 0.26% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… | |
| Modificada | Alta (8.8) | 0.38% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle Management | 6/10/2023 | 17/6/2026 | IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | |
| Modificada | Alta (7.5) | 0.57% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.66% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.60% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a stack overflow when handling a specially crafted message. | |
| Modificada | Media (5.5) | 0.23% | — | ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware | 22/5/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to… | |
| Modificada | Alta (8.8) | 1.6% | — | Aspiresoftware Open Aviation Strategic Engineering System | 16/9/2022 | 17/6/2026 | OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu. | |
| Modificada | Media (5.4) | 0.47% | — | IBM Engineering Test ManagementIBM Rational Quality Manager | 29/8/2022 | 17/6/2026 | IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210671. | |
| Modificada | Crítica (9.8) | 1.0% | — | Generalized Electric Vehicle Reverse Engineering Tool Project Generalized Electric Vehicle Reverse Engineering Tool | 3/8/2022 | 17/6/2026 | GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp. | |
| Modificada | Media (6.5) | 0.37% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310. | |
| Modificada | Media (6.5) | 0.86% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… |