Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
9810 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.5) | 0.10% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information. | |
| Recibida | Media (6.3) | 0.18% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a… | |
| Recibida | Media (6.1) | 0.09% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service. | |
| Recibida | Alta (7.2) | 0.52% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating… | |
| Recibida | Crítica (9.8) | 0.64% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system. | |
| Recibida | Alta (8.8) | 0.30% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive… | |
| Recibida | Crítica (9.8) | 0.53% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code. | |
| Recibida | Crítica (9.8) | 0.47% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system. | |
| Recibida | Crítica (9.8) | 0.53% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system. | |
| Aplazada | Media (6.3) | 0.37% | — | H Peter Anvin Tftp-hpaAI | 6/10/2026 | 6/10/2026 | tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler. | |
| Aplazada | Alta (7.2) | 0.46% | — | Publishpress CapabilitiesAI | 6/10/2026 | 6/10/2026 | Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | |
| Aplazada | Baja (2) | 0.23% | — | Phpgurukul User Registration Login AND User Management SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | HP ThinproAI | 5/10/2026 | 6/10/2026 | Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities. Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security… | |
| Pendiente de análisis | Crítica (9) | 0.27% | — | HPE Integrated Lights OUT 7AI | 5/10/2026 | 6/10/2026 | A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware. | |
| Aplazada | Alta (7.1) | 0.22% | 💥 PoC | PhprojectAI | 2/10/2026 | 6/10/2026 | Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess()… | |
| Aplazada | Media (5.4) | 0.18% | — | Publishpress SeriesAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3. | |
| Aplazada | Media (5.4) | 0.34% | — | Filamentphp FilamentAI | 1/10/2026 | 6/10/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up… | |
| Aplazada | Media (6.9) | 0.18% | — | Simple-php-router Simple PHP RouterAI | 30/9/2026 | 5/10/2026 | simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted… | |
| Pendiente de análisis | Baja (2.7) | 0.23% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers… | |
| Pendiente de análisis | Baja (3) | 0.10% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. | |
| Pendiente de análisis | Baja (3.3) | 0.09% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. | |
| Pendiente de análisis | Media (4.1) | 0.09% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported… | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information… | |
| Pendiente de análisis | Media (4.9) | 0.31% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes… | |
| Pendiente de análisis | Media (6.4) | 0.10% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. |