Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

383 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.38%—Hitachienergy Esoms1/11/202317/6/2026
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info,…
ModificadaMedia (5.3)0.38%—Hitachienergy Esoms1/11/202317/6/2026
The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.
ModificadaMedia (5.3)0.38%—Hitachienergy Esoms1/11/202317/6/2026
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
ModificadaMedia (4.3)0.36%—Hitachienergy Modular Advanced Control FOR Hvdc1/11/202317/6/2026
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
ModificadaMedia (6.5)0.49%—Hitachienergy Modular Advanced Control FOR Hvdc1/11/202317/6/2026
The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to McFeeder server. An authenticated malicious…
ModificadaAlta (7.5)0.62%—Hitachi OPS Center Common Services3/10/202317/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00.
ModificadaAlta (7.8)0.20%—Hitachi Jp1/performance Management3/10/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10-50-*; JP1/Performance Management - Agent Option for…
ModificadaMedia (5.5)0.18%—Hitachi OPS Center Administrator3/10/202317/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.
ModificadaMedia (4.9)0.28%—Hitachivantara Pentaho Business Analytics27/9/202317/6/2026
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext.
ModificadaAlta (8.8)0.61%—Hitachienergy Asset Suite11/9/202317/6/2026
A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vulnerability can be exploited by an authenticated user per-forming an Equipment Tag Out holder action (Accept, Release, and Clear) for another user and entering an arbitrary…
ModificadaAlta (7.5)0.46%—Hitachi Hirdb Server With Additional FunctionHitachi Hirdb Structured Data Access FacilityHitachi Hirdb Server29/8/202317/6/2026
Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server…
ModificadaAlta (7.8)0.20%—Hitachi Eh-view23/8/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This…
ModificadaMedia (5.5)0.20%—Hitachi Eh-view23/8/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Read vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially disclose information on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This vulnerability…
ModificadaAlta (7.8)0.20%—Hitachi Eh-view23/8/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This…
ModificadaAlta (7.8)0.20%—Hitachi Eh-view23/8/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially disclose information and execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the…
ModificadaAlta (7.5)0.71%—Hitachienergy Rtu500 Firmware26/7/202317/6/2026
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters…
ModificadaAlta (7.5)0.65%—Hitachienergy Rtu500 Firmware26/7/202317/6/2026
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately.…
ModificadaAlta (8.1)0.24%—Hitachi Device Manager18/7/202317/6/2026
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before 8.8.5-02.
ModificadaAlta (7.5)0.34%—Hitachi Device Manager18/7/202317/6/2026
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Interception.This issue affects Hitachi Device Manager: before 8.8.5-02.
ModificadaCrítica (9.8)0.53%—Hitachi Replication Manager18/7/202317/6/2026
Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Replication Manager: before 8.8.5-02.
ModificadaAlta (7.8)0.16%—Hitachi Compute Systems ManagerHitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage Manager+118/7/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning…
ModificadaMedia (4.4)0.24%—Hitachienergy Foxman-unHitachienergy Unem30/5/202317/6/2026
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information.
ModificadaMedia (4.3)0.38%—Hitachi Vantara PentahoHitachi Vantara Pentaho Business Analytics Server24/5/202317/6/2026
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list.
ModificadaAlta (8.8)0.63%—Hitachi Vantara PentahoHitachi Vantara Pentaho Business Analytics Server24/5/202317/6/2026
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
ModificadaMedia (6.1)0.38%—Hitachi OPS Center Analyzer23/5/202317/6/2026
Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00.
Orbitaley — Vulnerabilidades