Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

403 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.2%—NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+419/2/202016/6/2026
Nokogiri before 1.5.4 is vulnerable to XXE attacks
ModificadaCrítica (9.8)2.9%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+918/2/202016/6/2026
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
ModificadaAlta (7.1)0.78%—Hitachienergy Asset Suite17/2/202017/6/2026
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.
ModificadaAlta (7.5)6.4%—HP Asset ManagerHP Asset Manager Cloudsystem ChargebackHP Sitescope4/2/202017/6/2026
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability…
ModificadaMedia (6.1)0.66%—Redhat Subscription Asset Manager2/1/202017/6/2026
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
ModificadaMedia (6.5)0.43%—Redhat Subscription Asset Manager11/12/201917/6/2026
katello-headpin is vulnerable to CSRF in REST API
ModificadaCrítica (9.8)7.9%💥 ExploitNapc Xinet Elegant 6 Asset Library2/12/201917/6/2026
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
ModificadaMedia (6.5)0.72%—IBM Maximo Asset Management20/11/201917/6/2026
IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.
ModificadaMedia (6.5)2.2%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
ModificadaMedia (6.5)2.1%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
ModificadaMedia (5.4)0.67%—IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+524/10/201917/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
ModificadaMedia (4.3)0.99%—IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+69/10/201917/6/2026
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
ModificadaAlta (8.1)4.2%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaCrítica (9.1)4.4%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
ModificadaAlta (7.5)2.6%—IBM Maximo Asset Management17/7/201917/6/2026
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
ModificadaAlta (8)2.6%—IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+619/6/201917/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
ModificadaMedia (5.4)0.99%—IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+619/6/201917/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
ModificadaMedia (4.3)0.85%—IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+66/6/201917/6/2026
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
ModificadaBaja (2.1)0.31%—IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+66/6/201917/6/2026
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
ModificadaMedia (6.5)0.77%—IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+66/6/201917/6/2026
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
Orbitaley — Vulnerabilidades