Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.19% | — | Verve Asset ManagerAI | 20/1/2026 | 17/6/2026 | A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024. | |
| Aplazada | Alta (8.6) | 0.13% | — | Verve Asset ManagerAI | 20/1/2026 | 17/6/2026 | A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024. | |
| Aplazada | Alta (8.4) | 0.32% | — | Verve Asset ManagerAI | 11/11/2025 | 17/6/2026 | A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API. | |
| Aplazada | Crítica (10) | 1.7% | — | Asset ManagerAI | 5/8/2025 | 16/6/2026 | The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once… | |
| Aplazada | Alta (7.5) | 0.67% | — | Rockwellautomation Verve Asset ManagerAI | 31/3/2025 | 17/6/2026 | A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy Agentless Device Inventory (ADI) capability (deprecated since the 1.36 release) allows users to change a variable with inadequate sanitizing.… | |
| Modificada | Media (5.5) | 0.35% | — | Entechtaiwan Monitor Asset Manager | 24/5/2023 | 17/6/2026 | A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been… | |
| Modificada | Alta (7.5) | 1.7% | — | Melistechnology Melis-asset-manager | 11/10/2022 | 17/6/2026 | MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users… | |
| Modificada | Media (4.3) | 1.00% | — | IBM Rational Asset Manager | 29/9/2022 | 16/6/2026 | IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences. | |
| Modificada | Alta (8.2) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 16/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.… | |
| Modificada | Media (6.5) | 0.92% | — | IBM Infosphere Metadata Asset Manager | 4/9/2020 | 17/6/2026 | IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308. | |
| Modificada | Media (6.1) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880. | |
| Modificada | Media (5.4) | 0.78% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+15 | 17/4/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490. | |
| Modificada | Alta (7.5) | 2.2% | — | NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+4 | 19/2/2020 | 16/6/2026 | Nokogiri before 1.5.4 is vulnerable to XXE attacks | |
| Modificada | Alta (7.5) | 6.4% | — | HP Asset ManagerHP Asset Manager Cloudsystem ChargebackHP Sitescope | 4/2/2020 | 17/6/2026 | An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability… | |
| Modificada | Media (6.1) | 0.66% | — | Redhat Subscription Asset Manager | 2/1/2020 | 17/6/2026 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Subscription Asset Manager | 11/12/2019 | 17/6/2026 | katello-headpin is vulnerable to CSRF in REST API | |
| Modificada | Media (6.5) | 2.2% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | |
| Modificada | Media (6.5) | 2.1% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents | |
| Modificada | Crítica (9.8) | 1.6% | — | IBM Infosphere Information Server ON CloudIBM Infosphere Metadata Asset Manager | 10/4/2019 | 17/6/2026 | IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494. | |
| Modificada | Alta (7.8) | 1.7% | — | Kzsoftware Asset ManagerKzsoftware Training Manager | 5/9/2018 | 17/6/2026 | Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the… | |
| Modificada | Crítica (9.8) | 86% | — | Redhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+11 | 9/11/2017 | 17/6/2026 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat… | |
| Modificada | Media (6.1) | 0.75% | — | Redhat Subscription Asset Manager | 16/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Crítica (9.8) | 4.5% | — | HP Asset ManagerHP Asset Manager Cloudsystem Chargeback | 5/4/2016 | 17/6/2026 | HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. | |
| Modificada | Baja (2.1) | 0.38% | — | Numara Asset Manager | 26/10/2015 | 17/6/2026 | HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors. |