Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.3) | 0.15% | — | Opentext Service ManagerAI | 12/3/2025 | 17/6/2026 | Unquoted Search Path or Element vulnerability in OpenText™ Service Manager. The vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation. This issue affects Service Manager: 9.70, 9.71, 9.72. | |
| Aplazada | Baja (2.1) | 0.31% | — | Opentext Service ManagerAI | 12/3/2025 | 17/6/2026 | Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80. | |
| Modificada | Media (6.5) | 0.96% | — | Cybozu Remote Service Manager | 3/8/2023 | 17/6/2026 | Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition. | |
| Modificada | Alta (8.8) | 0.71% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | |
| Modificada | Alta (7.5) | 0.53% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue. | |
| Modificada | Alta (8.8) | 0.71% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | |
| Modificada | Media (5.4) | 0.35% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably. | |
| Modificada | Media (5.4) | 0.59% | — | Easyvista Service Manager | 20/10/2022 | 9/7/2026 | Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field. | |
| Modificada | Media (6.5) | 1.1% | — | Tibco Iway Service Manager | 2/8/2022 | 17/6/2026 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vulnerability that allows a low privileged attacker with network access to read arbitrary resources on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Media (5.4) | 0.50% | — | Tibco Iway Service Manager | 2/8/2022 | 17/6/2026 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system.… | |
| Modificada | Media (6.1) | 2.9% | — | Ivanti Service Manager | 1/2/2022 | 17/6/2026 | Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx. | |
| Modificada | Media (6.1) | 0.75% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.82% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors. | |
| Modificada | Media (5.4) | 0.72% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. | |
| Modificada | Media (5.3) | 0.99% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (6.5) | 1.5% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.56% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors. |