Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.19%—Verve Asset ManagerAI20/1/202617/6/2026
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
AplazadaAlta (8.6)0.13%—Verve Asset ManagerAI20/1/202617/6/2026
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.
AplazadaAlta (8.4)0.32%—Verve Asset ManagerAI11/11/202517/6/2026
A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API.
AplazadaCrítica (10)1.7%—Asset ManagerAI5/8/202516/6/2026
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once…
AplazadaAlta (7.5)0.67%—Rockwellautomation Verve Asset ManagerAI31/3/202517/6/2026
A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy Agentless Device Inventory (ADI) capability (deprecated since the 1.36 release) allows users to change a variable with inadequate sanitizing.…
ModificadaMedia (5.5)0.35%—Entechtaiwan Monitor Asset Manager24/5/202317/6/2026
A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been…
ModificadaAlta (7.5)1.7%—Melistechnology Melis-asset-manager11/10/202217/6/2026
MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users…
ModificadaMedia (4.3)1.00%—IBM Rational Asset Manager29/9/202216/6/2026
IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.
ModificadaAlta (8.2)0.89%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1616/9/202017/6/2026
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.…
ModificadaMedia (6.5)0.92%—IBM Infosphere Metadata Asset Manager4/9/202017/6/2026
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.
ModificadaMedia (5.4)0.67%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1617/4/202017/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
ModificadaMedia (6.1)0.89%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1617/4/202017/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
ModificadaMedia (5.4)0.78%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1517/4/202017/6/2026
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
ModificadaAlta (7.5)2.2%—NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+419/2/202016/6/2026
Nokogiri before 1.5.4 is vulnerable to XXE attacks
ModificadaAlta (7.5)6.4%—HP Asset ManagerHP Asset Manager Cloudsystem ChargebackHP Sitescope4/2/202017/6/2026
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability…
ModificadaMedia (6.1)0.66%—Redhat Subscription Asset Manager2/1/202017/6/2026
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
ModificadaMedia (6.5)0.43%—Redhat Subscription Asset Manager11/12/201917/6/2026
katello-headpin is vulnerable to CSRF in REST API
ModificadaMedia (6.5)2.2%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
ModificadaMedia (6.5)2.1%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
ModificadaCrítica (9.8)1.6%—IBM Infosphere Information Server ON CloudIBM Infosphere Metadata Asset Manager10/4/201917/6/2026
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.
ModificadaAlta (7.8)1.7%—Kzsoftware Asset ManagerKzsoftware Training Manager5/9/201817/6/2026
Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the…
ModificadaCrítica (9.8)86%—Redhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+119/11/201717/6/2026
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat…
ModificadaMedia (6.1)0.75%—Redhat Subscription Asset Manager16/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaCrítica (9.8)4.5%—HP Asset ManagerHP Asset Manager Cloudsystem Chargeback5/4/201617/6/2026
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ModificadaBaja (2.1)0.38%—Numara Asset Manager26/10/201517/6/2026
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.