Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.37%—Oracle AssetsAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this…
AnalizadaCrítica (9.9)0.43%—Oracle Iassets28/5/202621/7/2026
Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iAssets. While the vulnerability is in…
AplazadaAlta (8.8)1.0%—Dumb AssetsAI18/5/202614/7/2026
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and…
AplazadaMedia (5.3)0.40%—Silverstripe Assets ModuleAISilverstripe FrameworkAI16/4/202617/6/2026
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file…
AnalizadaAlta (7.2)0.79%—Atlassian Assets Discovery Data Center20/2/202417/6/2026
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects…
ModificadaMedia (6.5)0.55%—Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet29/1/202417/6/2026
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
ModificadaAlta (8.8)11%—Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server6/12/202317/6/2026
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
ModificadaMedia (5.4)0.68%—Silverstripe Asset AdminSilverstripe AssetsSilverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
ModificadaMedia (4.3)1.2%—Silverstripe Assets28/6/202217/6/2026
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
ModificadaAlta (7.2)1.2%—Thomsonreuters Fixed Assets CS3/12/201417/6/2026
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
ModificadaMedia (6.8)0.98%—EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Records Manager+520/8/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)1.8%—EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Webtop+420/8/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.