Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset ManagementIBM Change AND Configuration Management DatabaseIBM Maximo Service DeskIBM Tivoli Asset Management FOR IT+3 | 26/5/2014 | 17/6/2026 | IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database… | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset ManagementIBM Change AND Configuration Management DatabaseIBM Maximo Service DeskIBM Tivoli Asset Management FOR IT+3 | 26/5/2014 | 16/6/2026 | IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Service DeskIBM Tivoli Asset Management FOR ITIBM Tivoli IT Asset Management FOR IT+3 | 26/5/2014 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before… | |
| Modificada | Media (4.3) | 1.2% | — | Bestpractical Request TrackerBestpractical Rt-extension-mobileui | 5/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR GovernmentIBM Maximo FOR Life Sciences+8 | 18/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014,… | |
| Modificada | Baja (2.6) | 2.1% | — | Fusedpress Buddypress-extended-frienship-request | 29/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress, when the "Friend Connections" component is enabled, allows remote attackers to inject arbitrary web script or HTML via the friendship_request_message parameter to wp-admin/admin-ajax.php. NOTE:… | |
| Modificada | Media (4.3) | 1.2% | — | Bestpractical Request Tracker | 24/7/2013 | 16/6/2026 | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to bypass intended restrictions on reading keys in the product's keyring, and trigger outbound e-mail messages signed by an arbitrary stored secret key, by leveraging a UI e-mail signing privilege. | |
| Modificada | Media (4.3) | 0.64% | — | Bestpractical Request Tracker | 24/7/2013 | 16/6/2026 | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, does not ensure that the UI labels unencrypted messages as unencrypted, which might make it easier for remote attackers to spoof details of a message's origin or interfere with encryption-policy auditing via an e-mail… | |
| Modificada | Media (6.4) | 0.79% | — | Bestpractical Request Tracker | 24/7/2013 | 16/6/2026 | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cause a denial of service (loss of e-mail readability), via an e-mail message to a queue's address. | |
| Modificada | Media (4.3) | 1.1% | — | Bestpractical Request Tracker | 24/7/2013 | 16/6/2026 | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled with a "Sign by default" queue configuration, uses a queue's key for signing, which might allow remote attackers to spoof messages by leveraging the lack of authentication semantics. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Bestpractical Request Tracker | 10/5/2013 | 16/6/2026 | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and… | |
| Modificada | Media (6.5) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR IT+1 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Tivoli Service Request Manager+3 | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web… | |
| Modificada | Media (4) | 1.1% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via… | |
| Modificada | Media (6.8) | 2.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL… | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL… | |
| Modificada | Media (6.5) | 1.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via… |