Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.27% | — | Oracle Enterprise Asset Management | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Linear Asset Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Media (4.2) | 0.19% | — | Oracle Enterprise Asset Management | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Enterprise Asset Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Enterprise Asset Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Asset Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Enterprise Asset Management | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Openasset Digital Asset ManagementAI | 14/7/2026 | 15/7/2026 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Enterprise Asset Management | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Asset Management | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Media (6.5) | 0.33% | — | Oracle Peoplesoft Enterprise FIN IT Asset Management | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN IT Asset… | |
| Aplazada | Baja (2.1) | 0.22% | — | Opentext Digital Asset ManagementAI | 28/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Maximo Asset Management | 25/4/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Maximo Asset Management | 22/4/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Aplazada | Media (5.3) | 0.31% | — | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management AND Operations SystemAI | 1/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to… | |
| Aplazada | Media (6.9) | 0.43% | — | Baiyi Cloud Asset Management SystemAI | 21/2/2025 | 17/6/2026 | A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Media (6.9) | 0.47% | — | Baiyi Cloud Asset Management SystemAI | 19/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing of the file /wuser/admin.house.collect.php. The manipulation of the argument project_id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (6.5) | 0.34% | — | IBM Maximo Asset Management | 24/1/2025 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system. | |
| Analizada | Alta (7.5) | 0.79% | — | IBM Maximo Asset Management | 19/1/2025 | 17/6/2026 | IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (7.1) | 0.15% | — | Teamviewer Patch AND Asset ManagementAI | 11/12/2024 | 17/6/2026 | Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamViewer Patch & Asset Management is part of TeamViewer Remote Management. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Maximo Asset Management | 11/11/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Enterprise Asset Management | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Modificada | Baja (3.3) | 0.18% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 13/6/2024 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973. | |
| Aplazada | Media (6.5) | 0.39% | — | Opentext Service Management Automation XAIOpentext Asset Management XAIOpentext Hybrid Cloud Management XAI | 19/3/2024 | 17/6/2026 | Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05,… | |
| Aplazada | Media (6.5) | 0.34% | — | Opentext Service Management Automation XAIOpentext Asset Management XAI | 19/3/2024 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02,… | |
| Analizada | Alta (7.5) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 13/3/2024 | 17/6/2026 | IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075. |