Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.5% | 💥 PoC | Damstratechnology Smart Asset | 2/10/2020 | 17/6/2026 | An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password"). | |
| Modificada | Crítica (9.1) | 25% | 💥 PoC | Damstratechnology Smart Asset | 2/10/2020 | 17/6/2026 | Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers. | |
| Modificada | Alta (7.2) | 0.65% | — | Asset Performance Management Classic | 23/9/2020 | 17/6/2026 | GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the… | |
| Modificada | Media (5.3) | 0.90% | — | Asset Performance Management Classic | 23/9/2020 | 17/6/2026 | GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such functionality. An attacker can download sensitive data related to user accounts… | |
| Modificada | Alta (8.2) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 16/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.… | |
| Modificada | Media (4.3) | 0.48% | — | IBM Maximo Asset Management | 15/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 182436. | |
| Modificada | Alta (8.8) | 6.5% | — | IBM Maximo Asset Management | 15/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID:… | |
| Modificada | Media (6.3) | 0.83% | — | IBM Maximo Asset Management | 15/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437. | |
| Modificada | Media (6.5) | 0.92% | — | IBM Infosphere Metadata Asset Manager | 4/9/2020 | 17/6/2026 | IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Maximo Asset Management | 13/8/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 167288. | |
| Modificada | Alta (8.2) | 32% | 💥 Exploit | IBM Maximo Asset Management | 29/7/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484. | |
| Modificada | Alta (7.8) | 0.27% | — | IBM Maximo Asset Management | 13/7/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Maximo Asset Management | 26/6/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175121. | |
| Modificada | Media (6.3) | 0.96% | 💥 PoC | IBM Maximo Asset Management | 26/6/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961. | |
| Modificada | Alta (7.4) | 0.82% | — | IBM Maximo Asset Management | 8/6/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Maximo Asset Management | 12/5/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308. | |
| Modificada | Media (6.1) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880. | |
| Modificada | Media (5.4) | 0.78% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+15 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490. | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Financial Services Asset Liability Management | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 and 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.4) | 1.6% | — | Zohocorp Manageengine Assetexplorer | 23/3/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable… | |
| Modificada | Alta (7.2) | 6.0% | — | Zohocorp Manageengine Assetexplorer | 23/3/2020 | 17/6/2026 | Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges. | |
| Modificada | Media (4.3) | 0.87% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+3 | 24/2/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Maximo Asset Management | 20/2/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289. |