Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.4) | 0.25% | — | IBM Maximo Anywhere | 16/2/2022 | 17/6/2026 | IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494. | |
| Modificada | Media (4.6) | 0.24% | — | IBM Maximo Anywhere | 16/2/2022 | 17/6/2026 | IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: 161493. | |
| Modificada | Media (6.5) | 0.45% | — | IBM Maximo Anywhere | 16/2/2022 | 17/6/2026 | IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697. | |
| Modificada | Baja (3.5) | 0.33% | — | IBM Maximo Anywhere | 3/11/2020 | 17/6/2026 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the service. IBM X-Force ID: 161486 | |
| Modificada | Baja (2.4) | 0.32% | — | IBM Maximo Anywhere | 6/5/2020 | 17/6/2026 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199. | |
| Modificada | Media (4.3) | 0.35% | — | IBM Maximo Anywhere | 29/4/2020 | 17/6/2026 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631. | |
| Modificada | Media (4.3) | 0.35% | — | IBM Maximo Anywhere | 29/4/2020 | 17/6/2026 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Control DeskIBM Maximo AnywhereIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/2/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886. | |
| Modificada | Baja (2.4) | 0.37% | — | IBM Maximo Anywhere | 10/10/2019 | 17/6/2026 | IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Maximo Anywhere | 21/2/2018 | 17/6/2026 | IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132851. | |
| Modificada | Media (5) | 1.0% | — | IBM Maximo Anywhere | 26/7/2015 | 17/6/2026 | Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application. |