Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.34% | — | IBM Maximo Asset Management | 24/1/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system. | |
| Analizada | Alta (7.5) | 0.79% | — | IBM Maximo Asset Management | 19/1/2025 | 17/6/2026 | IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (7.1) | 0.15% | — | Teamviewer Patch AND Asset ManagementAI | 11/12/2024 | 17/6/2026 | Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamViewer Patch & Asset Management is part of TeamViewer Remote Management. | |
| Aplazada | Media (4.4) | 0.27% | — | Gabelivan Asset Cleanup Page Speed BoosterAI | 30/11/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Server Side Request Forgery.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.3.9.8. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Maximo Asset Management | 11/11/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (8.8) | 0.45% | — | Gabelivan Asset Cleanup | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Enterprise Asset Management | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Modificada | Baja (3.3) | 0.18% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 13/6/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973. | |
| Modificada | Alta (7) | 0.19% | — | Aveva PI Asset Framework Client | 12/6/2024 | 17/6/2026 | There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker. | |
| Aplazada | Alta (7.2) | 0.73% | — | SAP Asset AccountingAI | 9/4/2024 | 17/6/2026 | SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application. | |
| Aplazada | Media (6.5) | 0.39% | — | Opentext Service Management Automation XAIOpentext Asset Management XAIOpentext Hybrid Cloud Management XAI | 19/3/2024 | 17/6/2026 | Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05,… | |
| Aplazada | Media (6.5) | 0.34% | — | Opentext Service Management Automation XAIOpentext Asset Management XAI | 19/3/2024 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02,… | |
| Analizada | Alta (7.5) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 13/3/2024 | 17/6/2026 | IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075. | |
| Aplazada | Crítica (9.1) | 0.64% | — | Bentley Alim WEBAIBentley Assetwise Alim WEBAIBentley Assetwise Information Integrity ServerAI | 26/2/2024 | 17/6/2026 | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03. | |
| Analizada | Alta (7.2) | 0.79% | — | Atlassian Assets Discovery Data Center | 20/2/2024 | 17/6/2026 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects… | |
| Modificada | Crítica (9.8) | 0.55% | — | IBM Maximo Asset Management | 2/2/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073. | |
| Modificada | Media (6.5) | 0.55% | — | Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet | 29/1/2024 | 17/6/2026 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system. | |
| Modificada | Alta (8.8) | 0.29% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 19/1/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843. | |
| Modificada | Media (5.4) | 0.28% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 19/1/2024 | 17/6/2026 | IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 255288. | |
| Modificada | Alta (8.6) | 0.46% | — | Bentley Assetwise Alim FOR TransportationBentley EB System Management Console | 22/12/2023 | 17/6/2026 | Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before… | |
| Modificada | Alta (8.8) | 11% | — | Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server | 6/12/2023 | 17/6/2026 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.30% | — | Microfocus Asset Management XMicrofocus Service Management Automation X | 30/10/2023 | 17/6/2026 | Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user… | |
| Modificada | Alta (8.8) | 0.79% | — | Projectworlds Asset Management System | 28/9/2023 | 17/6/2026 | Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents. | |
| Modificada | Crítica (9.8) | 0.86% | — | Projectworlds Asset Management System | 28/9/2023 | 17/6/2026 | Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. |