Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.29% | — | Tanium Asset | 29/1/2026 | 17/6/2026 | Tanium addressed a SQL injection vulnerability in Asset. | |
| Aplazada | Alta (8.8) | 0.19% | — | Verve Asset ManagerAI | 20/1/2026 | 17/6/2026 | A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024. | |
| Aplazada | Alta (8.6) | 0.13% | — | Verve Asset ManagerAI | 20/1/2026 | 17/6/2026 | A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024. | |
| Aplazada | Alta (8.4) | 0.32% | — | Verve Asset ManagerAI | 11/11/2025 | 17/6/2026 | A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API. | |
| Analizada | Media (6.5) | 0.33% | — | Oracle Peoplesoft Enterprise FIN IT Asset Management | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN IT Asset… | |
| Aplazada | Media (6) | 0.29% | — | Hitachienergy Asset SuiteAI | 30/9/2025 | 17/6/2026 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application… | |
| Aplazada | Alta (8.1) | 0.26% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Aplazada | Crítica (10) | 1.7% | 💥 Exploit | Asset ManagerAI | 5/8/2025 | 16/6/2026 | The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once… | |
| Aplazada | Crítica (9.1) | 0.38% | — | Hitachienergy Asset SuiteAI | 30/5/2025 | 17/6/2026 | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded. | |
| Aplazada | Media (6.3) | 0.24% | — | Hitachienergy Asset SuiteAI | 30/5/2025 | 17/6/2026 | A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will cause JavaScript code supplied by the attacker to… | |
| Aplazada | Baja (2.1) | 0.22% | — | Opentext Digital Asset ManagementAI | 28/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Maximo Asset Management | 25/4/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Maximo Asset Management | 22/4/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Aplazada | Media (5.9) | 0.47% | — | Assetview CloudAIHammock AssetviewAI | 2/4/2025 | 17/6/2026 | AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by a remote unauthenticated attacker. | |
| Aplazada | Alta (8.2) | 0.51% | — | Assetview CloudAIHammock AssetviewAI | 2/4/2025 | 17/6/2026 | Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker. | |
| Aplazada | Alta (7.5) | 0.67% | — | Rockwellautomation Verve Asset ManagerAI | 31/3/2025 | 17/6/2026 | A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy Agentless Device Inventory (ADI) capability (deprecated since the 1.36 release) allows users to change a variable with inadequate sanitizing.… | |
| Aplazada | Media (5.3) | 0.31% | — | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management AND Operations SystemAI | 1/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to… | |
| Aplazada | Media (6.9) | 0.43% | — | Baiyi Cloud Asset Management SystemAI | 21/2/2025 | 17/6/2026 | A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters. | |
| Modificada | Media (6.5) | 0.43% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (6.5) | 0.40% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Aplazada | Media (6.9) | 0.47% | — | Baiyi Cloud Asset Management SystemAI | 19/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing of the file /wuser/admin.house.collect.php. The manipulation of the argument project_id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Alta (7) | 0.38% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user. | |
| Analizada | Alta (7.3) | 0.33% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages. | |
| Analizada | Crítica (9.3) | 0.37% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application. |