Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.24% | — | Tecnoteca CmdbuildAI | 10/5/2026 | 25/7/2026 | CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachments in the classes… | |
| Aplazada | Alta (7.2) | 0.35% | — | I-doit Open Source CmdbAI | 3/2/2026 | 17/6/2026 | i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's… | |
| Aplazada | Baja (2.3) | 0.22% | — | Opentext UcmdbAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker has high level access to UCMDB to create or update data with malicious scripts This issue affects uCMDB: 24.4. | |
| Aplazada | Alta (8.7) | 0.33% | — | Opentext Operations Bridge ManagerAIOpentext Operations Bridge SuiteAIOpentext UcmdbAI | 17/4/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. The vulnerability could allow authenticated attackers to elevate user privileges. This issue affects… | |
| Modificada | Media (6.5) | 4.6% | — | Glpi-project Cmdb | 16/4/2023 | 17/6/2026 | front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter. | |
| Modificada | Alta (8.8) | 1.1% | — | Device42 Cmdb | 17/8/2022 | 17/6/2026 | OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions. | |
| Modificada | Alta (7.5) | 18% | — | Device42 Cmdb | 17/8/2022 | 17/6/2026 | Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00. | |
| Modificada | Crítica (9.8) | 0.79% | — | Device42 Cmdb | 17/8/2022 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00. | |
| Modificada | Crítica (9.1) | 0.91% | — | Device42 Cmdb | 17/8/2022 | 17/6/2026 | An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions. | |
| Modificada | Media (6.5) | 0.77% | — | Tecnoteca Cmdbuild | 22/3/2022 | 17/6/2026 | In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table. | |
| Modificada | Alta (7.5) | 8.8% | — | HP Ucmdb Configuration Manager | 31/12/2018 | 17/6/2026 | Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities… | |
| Modificada | Media (5.4) | 0.66% | — | Microfocus Universal CmdbMicrofocus Universal Cmdb BrowserMicrofocus CMS Server | 23/5/2018 | 17/6/2026 | Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site… | |
| Modificada | Crítica (9.8) | 1.0% | — | Microfocus Ucmdb Configuration Manager | 24/4/2018 | 17/6/2026 | Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege. | |
| Modificada | Crítica (9.8) | 1.8% | — | Microfocus Ucmdb Configuration Manager | 22/2/2018 | 17/6/2026 | Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution. | |
| Modificada | Alta (7.5) | 1.9% | — | Microfocus Universal Cmdb Foundation Software | 20/2/2018 | 17/6/2026 | Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information. | |
| Modificada | Crítica (9.8) | 30% | — | HP Ucmdb Configuration Manager | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found. | |
| Modificada | Media (6.1) | 1.2% | — | HP Ucmdb Foundation Software | 5/10/2017 | 17/6/2026 | A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting. | |
| Modificada | Alta (8.8) | 4.7% | — | HP Ucmdb Foundation Software | 5/10/2017 | 17/6/2026 | A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution. | |
| Modificada | Media (6.1) | 0.91% | — | HP Ucmdb Configuration Manager | 30/9/2017 | 17/6/2026 | A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow cross-site scripting. | |
| Modificada | Crítica (9.8) | 4.4% | — | HP Ucmdb Configuration Manager | 30/9/2017 | 17/6/2026 | A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution. | |
| Modificada | Alta (8.4) | 1.4% | — | HP Ucmdb Browser | 8/1/2016 | 17/6/2026 | HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Broadcom Service DeskCA Cmdb | 27/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk 11.2 and CMDB 11.0 through 11.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "multiple web forms." |