Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.29% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.23% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.18% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Pendiente de análisis | Crítica (9.1) | 0.74% | — | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of… | |
| Pendiente de análisis | Crítica (9.1) | 0.58% | — | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the… | |
| Pendiente de análisis | Alta (8.5) | 0.25% | — | Hitachienergy Asset SuiteAI | 29/9/2026 | 29/9/2026 | Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. | |
| Pendiente de análisis | Media (5.1) | 0.25% | — | Hitachienergy Asset SuiteAI | 29/9/2026 | 29/9/2026 | Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Alta (7.4) | 0.41% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10… | |
| Analizada | Alta (8.5) | 0.14% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine. | |
| Analizada | Alta (8.5) | 0.14% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects. | |
| Analizada | Media (4.6) | 0.21% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a… | |
| Aplazada | Alta (8.3) | 0.35% | — | Hitachi Virtual Storage Platform E390AIHitachi Virtual Storage Platform E590AIHitachi Virtual Storage Platform E790AIHitachi Virtual Storage Platform E990AI+23 | 29/6/2026 | 29/6/2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H,… | |
| Aplazada | Media (6.8) | 0.38% | — | Hitachi Storage NavigatorAIHitachi Virtual Storage PlatformAIHitachi DkcmainAIHitachi SVPAI | 29/6/2026 | 29/9/2026 | Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, before DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi Virtual Storage… | |
| Aplazada | Baja (3.7) | 0.13% | — | Hitachi Virtual Storage Platform ONE BlockAI | 29/6/2026 | 29/9/2026 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. | |
| Aplazada | Alta (8.6) | 0.46% | — | Hitachi Virtual Storage PlatformAI | 19/6/2026 | 29/9/2026 | DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN… | |
| Analizada | Media (4.3) | 0.17% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those… | |
| Analizada | Media (6.3) | 0.15% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications. | |
| Analizada | Alta (7.7) | 0.20% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities. | |
| Aplazada | Media (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 26/5/2026 | 24/7/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… |