Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.95% | — | IBM Smartcloud Control DeskIBM Maximo Asset Management | 26/5/2014 | 16/6/2026 | frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Smartcloud Control DeskIBM Maximo Asset Management | 26/5/2014 | 16/6/2026 | CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+8 | 18/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014,… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified file-inclusion attacks via unknown vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049. | |
| Modificada | Media (4) | 1.1% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.4% | — | IBM Maximo Asset Management | 1/10/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Smartcloud Control Desk | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid. |