Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | IBM Maximo Asset Management | 18/2/2022 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892. | |
| Modificada | Media (6.1) | 0.82% | — | Asset Cleanup\ Page Speed Booster Project | 1/2/2022 | 17/6/2026 | The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.80% | — | Asset Cleanup\ Page Speed Booster Project | 1/2/2022 | 17/6/2026 | The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 30/8/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 27/8/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694. | |
| Modificada | Crítica (9.8) | 1.7% | — | IBM Maximo Asset Management | 12/8/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243. | |
| Modificada | Media (6.5) | 1.2% | — | Jump-technology Asset Management | 3/8/2021 | 17/6/2026 | An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal. | |
| Modificada | Alta (8.8) | 2.3% | — | Jump-technology Asset Management | 3/8/2021 | 17/6/2026 | An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially leading to remote code and command execution. | |
| Modificada | Alta (7.7) | 0.90% | — | Jump-technology Asset Management | 3/8/2021 | 17/6/2026 | An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the listing of the content of the remote file system. This can be used to identify the complete server filesystem structure, i.e., identifying all the directories and files. | |
| Modificada | Crítica (9.8) | 7.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the… | |
| Modificada | Alta (7.5) | 1.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request… | |
| Modificada | Alta (7.5) | 4.5% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the… | |
| Modificada | Media (5.4) | 0.51% | — | Hitachiabb-powergrids Ellipse Asset Performance Management | 14/6/2021 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and… | |
| Modificada | Media (5.4) | 0.52% | — | IBM Maximo Asset Management | 19/5/2021 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522. | |
| Modificada | Alta (8.1) | 1.0% | — | Oracle Enterprise Asset Management | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Modificada | Media (5.3) | 2.3% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application. | |
| Modificada | Alta (8.8) | 2.2% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection. | |
| Modificada | Media (6.1) | 0.78% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks. | |
| Modificada | Alta (8.8) | 1.1% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions. | |
| Modificada | Media (6.1) | 1.5% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks. | |
| Modificada | Alta (7.5) | 2.5% | — | Openasset Digital Asset Management | 14/12/2020 | 9/7/2026 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls. | |
| Modificada | Media (4.8) | 0.31% | — | IBM Maximo Spatial Asset Management | 9/11/2020 | 17/6/2026 | IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024. | |
| Modificada | Baja (3.3) | 0.32% | — | IBM Maximo Spatial Asset Management | 9/11/2020 | 17/6/2026 | IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023. | |
| Modificada | Crítica (9.8) | 2.7% | — | IBM Maximo Asset Management | 5/10/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995. | |
| Modificada | Crítica (9.8) | 0.91% | 💥 PoC | Damstratechnology Smart Asset | 2/10/2020 | 17/6/2026 | An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header. |