Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

92 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.2)0.46%—Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could…
AnalizadaMedia (5.2)0.14%—Hitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager25/2/202617/6/2026
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before…
AplazadaAlta (7.5)0.27%—Silabs Simplicity Device Manager ToolAI10/2/202617/6/2026
The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Manager tool running in…
AplazadaAlta (8.5)0.18%—Motorola Device ManagerAI27/1/202617/6/2026
Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service…
AplazadaAlta (8.5)0.18%—Motorola Device ManagerAI27/1/202617/6/2026
Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.
AplazadaAlta (7.4)0.17%—Silabs Simplicity Device ManagerAI4/12/202517/6/2026
The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.
AnalizadaMedia (4.8)0.18%—Axis Camera Station PROAxis Device Manager11/7/202517/6/2026
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
AnalizadaMedia (6.8)0.37%—Axis Device Manager11/7/202517/6/2026
The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.
AnalizadaCrítica (9)0.62%—Axis Camera StationAxis Camera Station PROAxis Device Manager11/7/202517/6/2026
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
AplazadaBaja (3.9)0.14%—Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI15/5/202517/6/2026
Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaMedia (5.3)0.16%—Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI15/5/202517/6/2026
Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaAlta (8.7)0.38%—Hitachi JP1 IT Desktop Management 2 Smart Device ManagerAI15/5/202517/6/2026
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaAlta (8.3)0.33%—Cisco IOS SoftwareAICisco Industrial Ethernet Switch Device ManagerAI7/5/202517/6/2026
A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending…
AplazadaCrítica (9.4)0.97%—Honeywell Onewireless Wireless Device ManagerAI6/2/202517/6/2026
Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command…
AplazadaMedia (6.7)0.17%—Hitachi Device ManagerAI6/8/202417/6/2026
Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.
ModificadaAlta (7.5)0.41%—Hitachi Device Manager16/1/202417/6/2026
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
ModificadaAlta (7.5)0.44%—Hitachi Device Manager16/1/202417/6/2026
Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.
ModificadaAlta (7.2)4.6%—Kyocera Device Manager10/1/202417/6/2026
Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. It allows administrators to configure the backup location of the database used by the application. Attempting to change this location to a UNC path via the GUI…
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (7.5)0.98%—Ncsist Mobile Device Manager3/11/202317/6/2026
NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.
ModificadaCrítica (9.8)1.1%—Maxiguvenlik General Device Manager25/9/202317/6/2026
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
ModificadaAlta (8.1)0.24%—Hitachi Device Manager18/7/202317/6/2026
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before 8.8.5-02.
ModificadaAlta (7.5)0.34%—Hitachi Device Manager18/7/202317/6/2026
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Interception.This issue affects Hitachi Device Manager: before 8.8.5-02.
ModificadaAlta (7.8)0.16%—Hitachi Compute Systems ManagerHitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage Manager+118/7/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning…
ModificadaAlta (8.8)1.6%—HP Device Manager12/6/202317/6/2026
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.