Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/3/2012 | 16/6/2026 | Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component. | |
| Modificada | Media (4) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2,… | |
| Modificada | Media (6.5) | 1.7% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management… | |
| Modificada | Media (6.8) | 1.0% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter. | |
| Modificada | Media (5) | 2.6% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers… | |
| Modificada | Alta (10) | 7.5% | — | HP Business Service Automation Essentials | 21/9/2011 | 16/6/2026 | Unspecified vulnerability in HP Business Service Automation (BSA) Essentials 2.01 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Forefront Client SecurityMicrosoft Forefront Endpoint Protection 2010Microsoft Malicious Software Removal ToolMicrosoft Malware Protection Engine+3 | 25/2/2011 | 16/6/2026 | Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified… | |
| Modificada | Alta (10) | 6.8% | — | BMC Performance Analysis FOR ServersBMC Performance Assurance FOR ServersBMC Performance Assurance FOR Virtual ServersBMC Performance Analyzer FOR Servers+2 | 10/2/2011 | 16/6/2026 | Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management… | |
| Modificada | Alta (7.5) | 2.6% | — | HP Storage Essentials | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in HP Storage Essentials before 6.3.0, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (6.5) | 1.3% | — | HP Storage Essentials | 21/4/2009 | 16/6/2026 | Unspecified vulnerability in Secure NaviCLI in HP Storage Essentials 6.0.2 through 6.0.4 allows remote authenticated users to obtain "access" or "extended privileges" via unknown vectors. | |
| Modificada | Media (6.8) | 0.29% | — | Citrix Access EssentialsCitrix Presentation ServerCitrix Xenapp | 22/10/2008 | 16/6/2026 | Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as… | |
| Modificada | Media (6.5) | 1.4% | — | Citrix Access EssentialsCitrix Presentation ServerCitrix Desktop ServerCitrix Metaframe Presentation Server | 18/5/2008 | 16/6/2026 | Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors. | |
| Modificada | Media (5) | 1.1% | — | Citrix Presentation ServerCitrix Access EssentialsCitrix Desktop Server | 18/5/2008 | 16/6/2026 | Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions. | |
| Modificada | Alta (10) | 3.7% | — | HP Storage Essentials SRM EnterpriseHP Storage Essentials SRM Standard | 12/2/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors. | |
| Modificada | Alta (10) | 73% | — | Citrix Access EssentialsCitrix Desktop ServerCitrix Metaframe Presentation ServerCitrix Presentation Server | 18/1/2008 | 16/6/2026 | Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or… | |
| Modificada | Alta (10) | 2.8% | — | Citrix Access EssentialsCitrix Metaframe | 24/5/2007 | 16/6/2026 | The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string. | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Learning EssentialsMicrosoft OfficeMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 13/2/2007 | 16/6/2026 | The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which… | |
| Modificada | Alta (10) | 2.5% | — | GFI MailessentialsGFI Mailsecurity | 3/1/2005 | 16/6/2026 | A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or… | |
| Modificada | Alta (10) | 2.1% | — | Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD1 | 20/10/2003 | 16/6/2026 | CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages. | |
| Modificada | Alta (10) | 2.1% | — | Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD1 | 20/10/2003 | 16/6/2026 | CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter. | |
| Modificada | Media (4.3) | 0.66% | — | Citrix Access EssentialsCitrix Metaframe Presentation ServerCitrix Presentation Server | 31/12/2002 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an… |