Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.17% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center Analyzer Viewpoint OVFAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 11.0.0-04. | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.37% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Aplazada | Alta (7.1) | 0.30% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 3/12/2024 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01. | |
| Analizada | Alta (7.8) | 0.20% | — | Hitachi OPS Center Common Services | 27/8/2024 | 17/6/2026 | Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01. | |
| Analizada | Media (6.5) | 0.20% | — | Hitachi OPS Center Common Services | 2/7/2024 | 17/6/2026 | Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00. | |
| Analizada | Alta (7.5) | 0.55% | — | Common-services SO Flexibilite | 3/3/2024 | 17/6/2026 | An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file. | |
| Analizada | Alta (7.8) | 0.19% | — | Aveva Platform Common Services | 29/2/2024 | 17/6/2026 | The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL. | |
| Analizada | Media (5.9) | 0.39% | — | Common-services SO Flexibilite | 27/2/2024 | 17/6/2026 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. | |
| Modificada | Crítica (9.8) | 0.51% | — | Common-services Soliberte | 14/12/2023 | 17/6/2026 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | |
| Modificada | Alta (7.5) | 0.76% | — | Common-services Sonice Retour | 17/11/2023 | 17/6/2026 | In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a… | |
| Modificada | Alta (7.5) | 0.58% | — | Common-services Sonice Etiquetage | 18/10/2023 | 17/6/2026 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can… | |
| Modificada | Alta (7.5) | 0.52% | — | Hitachi OPS Center Common Services | 3/10/2023 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00. | |
| Modificada | Alta (7.8) | 0.22% | — | Aveva Batch ManagementAveva Enterprise Data ManagementAveva Manufacturing Execution SystemAveva Mobile Operator+3 | 27/7/2022 | 17/6/2026 | AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path. | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… |