Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.88% | — | Hitachi Raid Manager Storage Replication Adapter | 6/9/2022 | 17/6/2026 | Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior… | |
| Modificada | Alta (7.5) | 1.1% | — | Hitachi Hc-ip9100hd Firmware | 29/8/2022 | 17/6/2026 | Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traversal via a crafted GET request to the endpoint /ptippage.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the issue. | |
| Modificada | Alta (7.5) | 0.88% | — | Hitachi Hc-ip9100hd Firmware | 29/8/2022 | 17/6/2026 | An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encoder) and bellow allows attckers to remotely reboot the device via a crafted POST request to the endpoint /ptipupgrade.cgi. Security information ID hitachi-sec-2022-001… | |
| Modificada | Alta (8.8) | 0.48% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker… | |
| Modificada | Alta (8.8) | 0.22% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain… | |
| Modificada | Media (6.7) | 0.17% | — | Hitachienergy Txpert HUB Coretec 4 Firmware | 7/6/2022 | 17/6/2026 | A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious firmware to the product. This issue affects:… | |
| Modificada | Media (6.7) | 0.26% | — | Hitachienergy Txpert HUB Coretec 4 Firmware | 7/6/2022 | 17/6/2026 | Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system. This issue affects: Hitachi Energy TXpert… | |
| Modificada | Media (6.7) | 0.22% | — | Hitachienergy Txpert HUB Coretec 4 Firmware | 7/6/2022 | 17/6/2026 | A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized actor to change an existing user password,… | |
| Modificada | Alta (7.5) | 0.99% | — | ABB Rtu500 FirmwareHitachienergy Rtu500 Firmware | 2/5/2022 | 17/6/2026 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is… | |
| Modificada | Media (5.4) | 0.62% | — | Hitachienergy Ellipse Enterprise Asset Management | 11/3/2022 | 17/6/2026 | An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential… | |
| Modificada | Media (6.1) | 0.57% | — | Hitachienergy Ellipse Enterprise Asset Management | 11/3/2022 | 17/6/2026 | An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials. | |
| Modificada | Alta (7.5) | 0.73% | — | Hitachi Linkone | 28/1/2022 | 17/6/2026 | Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further exploitation. This issue affects: Hitachi… | |
| Modificada | Alta (7.5) | 0.73% | — | Hitachi Linkone | 28/1/2022 | 17/6/2026 | Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26. | |
| Modificada | Media (5.3) | 0.67% | — | Hitachi Linkone | 28/1/2022 | 17/6/2026 | Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26. | |
| Modificada | Media (5.4) | 0.40% | — | Hitachi Linkone | 25/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26. | |
| Modificada | Alta (7.5) | 0.99% | — | Hitachienergy Fox615 FirmwareHitachienergy Xcm20 Firmware | 2/12/2021 | 17/6/2026 | Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects: Hitachi Energy FOX61x versions prior to… | |
| Modificada | Alta (7.1) | 0.66% | — | Hitachienergy Fox615 FirmwareHitachienergy Xcm20 Firmware | 2/12/2021 | 17/6/2026 | Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A. | |
| Modificada | Alta (7.5) | 0.95% | — | Hitachienergy Rtu500 Firmware | 26/11/2021 | 17/6/2026 | Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI… | |
| Modificada | Alta (7.2) | 1.8% | — | Hitachienergy Gms600 FirmwareHitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io Firmware+1 | 18/11/2021 | 17/6/2026 | Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow… | |
| Modificada | Alta (8.1) | 0.67% | — | Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io Firmware | 18/11/2021 | 17/6/2026 | Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during the booting process where an older version… | |
| Modificada | Alta (7.1) | 0.26% | — | Hitachienergy Counterparty Settlements AND BillingHitachienergy Retail Operations | 17/11/2021 | 17/6/2026 | Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data… | |
| Modificada | Alta (7.2) | 2.3% | — | Hitachi Vantara Pentaho | 8/11/2021 | 17/6/2026 | UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution). | |
| Modificada | Crítica (9.8) | 5.9% | — | Hitachi Vantara Pentaho | 8/11/2021 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI. | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default… | |
| Modificada | Media (6.5) | 1.4% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection… |