Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.0% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+2 | 10/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the… | |
| Modificada | Media (4.3) | 1.2% | — | Best Practical Solutions Request Tracker | 15/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM… | |
| Modificada | Media (4) | 1.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2,… | |
| Modificada | Media (6.5) | 1.7% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management… | |
| Modificada | Media (6.8) | 1.0% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and… | |
| Modificada | Media (5) | 2.6% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+2 | 13/3/2012 | 16/6/2026 | IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers… | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | American Financing Link Request Contact Form | 12/6/2007 | 16/6/2026 | Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Request IT | 12/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | |
| Modificada | Alta (7.8) | 1.3% | — | Capital Request Forms | 12/2/2007 | 16/6/2026 | Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc. | |
| Modificada | Media (5) | 1.9% | — | BMC Remedy Action Request System | 18/1/2007 | 16/6/2026 | BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Lotfian Request FOR Travel | 14/12/2006 | 16/6/2026 | SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter. | |
| Modificada | Media (5) | 1.2% | — | Best Practical Solutions Request Tracker | 4/5/2006 | 16/6/2026 | RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message. | |
| Modificada | Baja (2.6) | 0.90% | — | Geekforgod.net Prayer Request Board | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field. | |
| Modificada | Media (6.8) | 1.2% | — | Best Practical Solutions Request Tracker | 27/5/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Oddsock Song Requester | 4/10/2002 | 16/6/2026 | Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments. |