Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+4 | 19/2/2020 | 16/6/2026 | Nokogiri before 1.5.4 is vulnerable to XXE attacks | |
| Modificada | Crítica (9.8) | 2.9% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+9 | 18/2/2020 | 16/6/2026 | A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access. | |
| Modificada | Alta (7.1) | 0.78% | — | Hitachienergy Asset Suite | 17/2/2020 | 17/6/2026 | Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly. | |
| Modificada | Alta (7.5) | 6.4% | — | HP Asset ManagerHP Asset Manager Cloudsystem ChargebackHP Sitescope | 4/2/2020 | 17/6/2026 | An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability… | |
| Modificada | Media (6.1) | 0.66% | — | Redhat Subscription Asset Manager | 2/1/2020 | 17/6/2026 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Subscription Asset Manager | 11/12/2019 | 17/6/2026 | katello-headpin is vulnerable to CSRF in REST API | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Napc Xinet Elegant 6 Asset Library | 2/12/2019 | 17/6/2026 | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used. | |
| Modificada | Media (6.5) | 0.72% | — | IBM Maximo Asset Management | 20/11/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586. | |
| Modificada | Media (6.5) | 2.2% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | |
| Modificada | Media (6.5) | 2.1% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents | |
| Modificada | Media (5.4) | 0.67% | — | IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+5 | 24/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070. | |
| Modificada | Media (4.3) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 9/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. | |
| Modificada | Alta (8.1) | 4.2% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Modificada | Crítica (9.1) | 4.4% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | IBM Maximo Asset Management | 17/7/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. | |
| Modificada | Alta (8) | 2.6% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. | |
| Modificada | Media (5.4) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949. | |
| Modificada | Media (4.3) | 0.85% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. | |
| Modificada | Media (6.5) | 0.77% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. |