Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.37% | — | Oracle AssetsAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Iassets | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iAssets. While the vulnerability is in… | |
| Aplazada | Alta (8.8) | 1.0% | — | Dumb AssetsAI | 18/5/2026 | 14/7/2026 | DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and… | |
| Aplazada | Media (5.3) | 0.40% | — | Silverstripe Assets ModuleAISilverstripe FrameworkAI | 16/4/2026 | 17/6/2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file… | |
| Analizada | Alta (7.2) | 0.79% | — | Atlassian Assets Discovery Data Center | 20/2/2024 | 17/6/2026 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects… | |
| Modificada | Media (6.5) | 0.55% | — | Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet | 29/1/2024 | 17/6/2026 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system. | |
| Modificada | Alta (8.8) | 11% | — | Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server | 6/12/2023 | 17/6/2026 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. | |
| Modificada | Media (5.4) | 0.68% | — | Silverstripe Asset AdminSilverstripe AssetsSilverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | |
| Modificada | Media (4.3) | 1.2% | — | Silverstripe Assets | 28/6/2022 | 17/6/2026 | Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content. | |
| Modificada | Alta (7.2) | 1.2% | — | Thomsonreuters Fixed Assets CS | 3/12/2014 | 17/6/2026 | The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program. | |
| Modificada | Media (6.8) | 0.98% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Records Manager+5 | 20/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.8% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Webtop+4 | 20/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter. |