Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.58% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 20/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to hijack the authentication of… | |
| Modificada | Media (5.8) | 1.8% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 16/7/2015 | 17/6/2026 | Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to redirect users to arbitrary web sites and conduct… | |
| Modificada | Media (6.5) | 2.4% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5… | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web… | |
| Modificada | Alta (7.5) | 18% | — | Dell Asset Manager | 24/2/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx. | |
| Modificada | Alta (7.5) | 2.8% | — | EMC Documentum Digital Asset Manager | 6/6/2014 | 17/6/2026 | The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on querying objects via a crafted parameter in a query string. | |
| Analizada | Alta (7.5) | 54% | ⚠ Explotación activa💥 PoC | Redhat Subscription Asset ManagerRedhat Enterprise Linux ServerRubyonrails Rails | 7/5/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request. | |
| Modificada | Media (4) | 7.3% | 💥 Exploit | Mcafee Asset Manager | 24/3/2014 | 17/6/2026 | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Mcafee Asset Manager | 24/3/2014 | 17/6/2026 | SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter). | |
| Modificada | Alta (9.3) | 1.6% | — | Redhat Subscription Asset Manager | 23/12/2013 | 17/6/2026 | Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors. | |
| Modificada | Media (4.3) | 1.0% | — | EMC Documentum TaskspaceEMC Documentum Capital ProjectsEMC Documentum WDKEMC Documentum Digital Asset Manager+3 | 6/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum… | |
| Modificada | Media (4.3) | 1.9% | — | Redhat Subscription Asset Manager | 2/4/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Baja (2.1) | 0.42% | — | Candlepinproject CandlepinRedhat Subscription Asset Manager | 2/4/2013 | 16/6/2026 | Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests. | |
| Modificada | Media (4.3) | 0.84% | — | IBM Rational Asset Manager | 8/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Asset Manager before 7.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.39% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 23/7/2007 | 16/6/2026 | Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges. | |
| Modificada | Alta (9.3) | 4.7% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of… | |
| Modificada | Alta (10) | 7.8% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 16/5/2007 | 16/6/2026 | Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet. | |
| Modificada | Media (5.8) | 1.3% | — | John Frank Asset Manager | 30/5/2006 | 16/6/2026 | ** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in John Frank Asset Manager (AssetMan) 2.4a and earlier allows remote attackers to inject arbitrary web script or HTML via "any of its input." NOTE: the original disclosure is based on… | |
| Modificada | Alta (7.5) | 2.0% | — | Yusasp WEB Asset Manager | 18/5/2005 | 16/6/2026 | YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp. |