Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 563 respecto a la semana anterior
Críticas / altas1444▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

403 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.25%—Hitachienergy Asset SuiteAI29/9/202629/9/2026
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Pendiente de análisisMedia (5.1)0.25%—Hitachienergy Asset SuiteAI29/9/202629/9/2026
Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production…
AplazadaMedia (5.5)0.29%—Assetcleanup Asset Cleanup Page Speed BoosterAI25/9/202625/9/2026
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations…
AplazadaAlta (7.2)0.24%—Assetcleanup Asset Cleanuo Page Speed BoosterAI19/9/202621/9/2026
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.1)0.13%—Assetwp Asset Cleanup Page Speed BoosterAI17/9/202617/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Pendiente de análisisAlta (7.2)0.45%—Tanium AssetAI16/9/202618/9/2026
Tanium addressed a SQL injection vulnerability in Asset.
Pendiente de análisisAlta (7.2)0.45%—Tanium AssetAI16/9/202618/9/2026
Tanium addressed a SQL injection vulnerability in Asset.
Pendiente de análisisMedia (6.5)0.37%—Oracle AssetsAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this…
AnalizadaAlta (7.6)0.27%—Oracle Enterprise Asset Management18/8/20263/9/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Linear Asset Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AplazadaBaja (2.1)0.64%—Assimp Open Asset Import LibraryAI17/8/202620/8/2026
A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may…
AnalizadaMedia (4.2)0.19%—Oracle Enterprise Asset Management21/7/20263/8/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaMedia (5.9)0.33%—Oracle Enterprise Asset Management21/7/202628/7/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaMedia (5.4)0.21%—Oracle Enterprise Asset Management21/7/202628/7/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaAlta (8.8)0.43%—Oracle Enterprise Asset Management21/7/202628/7/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaMedia (5.4)0.23%—Oracle Enterprise Asset Management21/7/20263/8/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset…
AplazadaCrítica (9.8)1.1%—Openasset Digital Asset ManagementAI14/7/202615/7/2026
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
AplazadaBaja (2.1)0.40%—Assimp Open Asset Import LibraryAI3/7/20266/7/2026
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation causes double free. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.1)0.38%—Oracle Enterprise Asset Management17/6/202617/6/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaAlta (8.8)0.43%—Oracle Enterprise Asset Management17/6/202617/6/2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset…
AnalizadaCrítica (9.9)0.43%—Oracle Iassets28/5/202621/7/2026
Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iAssets. While the vulnerability is in…
AplazadaAlta (8.8)1.0%—Dumb AssetsAI18/5/202614/7/2026
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and…
AplazadaMedia (5.3)0.38%—Gabelivan Asset Cleanup Page Speed BoosterAI12/5/202617/6/2026
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.4.0.3.
AplazadaMedia (5.5)0.59%—Flux159 Mcp-game-asset-genAI1/5/202617/6/2026
A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Interface. The manipulation of the argument statusFile results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.…
AplazadaMedia (5.3)0.40%—Silverstripe Assets ModuleAISilverstripe FrameworkAI16/4/202617/6/2026
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file…
AnalizadaAlta (8.8)0.25%—Tanium Asset20/2/202617/6/2026
Tanium addressed a SQL injection vulnerability in Asset.