Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.0%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Service DeskIBM Smartcloud Control Desk+210/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the…
ModificadaMedia (4.3)1.2%—Best Practical Solutions Request Tracker15/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.9%—IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+213/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM…
ModificadaMedia (4)1.2%—IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+213/3/201216/6/2026
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2,…
ModificadaMedia (6.5)1.7%—IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+213/3/201216/6/2026
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management…
ModificadaMedia (6.8)1.0%—IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+213/3/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and…
ModificadaMedia (5)2.6%—IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Tivoli Asset Management FOR ITIBM Trivoli Service Request Manager+213/3/201216/6/2026
IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers…
ModificadaAlta (7.5)3.0%💥 ExploitAmerican Financing Link Request Contact Form12/6/200716/6/2026
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.
ModificadaMedia (6.8)3.2%💥 ExploitRequest IT12/4/200716/6/2026
PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
ModificadaAlta (7.8)1.3%—Capital Request Forms12/2/200716/6/2026
Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.
ModificadaMedia (5)1.9%—BMC Remedy Action Request System18/1/200716/6/2026
BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.
ModificadaAlta (7.5)1.1%💥 ExploitLotfian Request FOR Travel14/12/200616/6/2026
SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter.
ModificadaMedia (5)1.2%—Best Practical Solutions Request Tracker4/5/200616/6/2026
RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.
ModificadaBaja (2.6)0.90%—Geekforgod.net Prayer Request Board21/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.
ModificadaMedia (6.8)1.2%—Best Practical Solutions Request Tracker27/5/200316/6/2026
Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.
ModificadaMedia (5)3.5%💥 ExploitOddsock Song Requester4/10/200216/6/2026
Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments.
Orbitaley — Vulnerabilidades