Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Alta (7.8) | 0.29% | — | Siemens Simaris Configuration | 9/2/2021 | 17/6/2026 | A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permissions are configured for the application folder and subfolders which could allow an attacker to gain persistence or potentially escalate privileges should a user with… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+7 | 27/1/2021 | 17/6/2026 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+7 | 27/1/2021 | 17/6/2026 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+7 | 27/1/2021 | 17/6/2026 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457. | |
| Modificada | Media (5.4) | 0.82% | — | IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+7 | 27/1/2021 | 17/6/2026 | IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID:… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Collaborative Lifecycle ManagementIBM Engineering InsightsIBM Engineering Lifecycle ManagementIBM Engineering Requirements Management Doors Next+7 | 27/1/2021 | 17/6/2026 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434. | |
| Modificada | Crítica (9.8) | 2.1% | — | Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader | 19/1/2021 | 17/6/2026 | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the… | |
| Modificada | Media (4.3) | 0.83% | — | Jenkins AWS Global Configuration | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration. | |
| Modificada | Alta (7.8) | 0.41% | — | Eaton 9000x Programming AND Configuration Software | 30/9/2020 | 17/6/2026 | A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL. | |
| Modificada | Alta (8.2) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 16/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.… | |
| Modificada | Alta (7.8) | 0.38% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification. | |
| Modificada | Alta (7.8) | 0.22% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure,… | |
| Modificada | Alta (7.8) | 0.27% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a… | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Configuration Manager | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Configuration Manager product of Oracle Enterprise Manager (component: Discovery and collection script). The supported version that is affected is 12.1.2.0.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configuration… | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,… | |
| Modificada | Alta (7.5) | 1.4% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.… | |
| Modificada | Alta (7.5) | 6.0% | — | PerlNetapp Oncommand Workflow AutomationNetapp Snap Creator FrameworkFedoraproject Fedora+12 | 5/6/2020 | 17/6/2026 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. | |
| Modificada | Alta (8.6) | 4.9% | — | PerlFedoraproject FedoraOpensuse LeapNetapp Oncommand Workflow Automation+13 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. | |
| Modificada | Alta (8.2) | 11% | — | PerlFedoraproject FedoraOpensuse LeapOracle Communications Billing AND Revenue Management+11 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308. | |
| Modificada | Media (6.1) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880. | |
| Modificada | Media (5.4) | 0.78% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+15 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Binary Configuration Tool | 15/4/2020 | 17/6/2026 | Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. |