Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.5)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.
RecibidaMedia (6.3)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a…
RecibidaMedia (6.1)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service.
RecibidaAlta (7.2)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating…
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.
RecibidaAlta (8.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive…
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
Pendiente de análisisCrítica (9)0.27%—HPE Integrated Lights OUT 7AI5/10/20266/10/2026
A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
Pendiente de análisisBaja (2.7)0.23%—HPE Networking Instant ONAI29/9/202630/9/2026
A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers…
Pendiente de análisisBaja (3)0.10%—HPE Networking Instant ONAI29/9/202630/9/2026
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Pendiente de análisisBaja (3.3)0.09%—HPE Networking Instant ONAI29/9/202630/9/2026
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Pendiente de análisisMedia (4.1)0.09%—HPE Networking Instant ONAI29/9/202630/9/2026
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported…
Pendiente de análisisMedia (4.8)0.29%—HPE Networking Instant ONAI29/9/202630/9/2026
A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information…
Pendiente de análisisMedia (4.9)0.31%—HPE Networking Instant ONAI29/9/202630/9/2026
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes…
Pendiente de análisisMedia (6.4)0.10%—HPE Networking Instant ONAI29/9/20261/10/2026
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Pendiente de análisisMedia (6.5)0.32%—HPE Networking Instant ONAI29/9/202630/9/2026
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected…
Pendiente de análisisMedia (6.5)0.21%—HPE Instant ON APSAI29/9/202630/9/2026
An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send…
Pendiente de análisisMedia (6.6)0.42%—HPE Networking Instant ON APSAI29/9/20261/10/2026
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the…
Pendiente de análisisAlta (7.2)0.55%—HPE Networking Instant ON Access PointAI29/9/20266/10/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
Pendiente de análisisAlta (7.2)0.98%—HPE Networking Instant ONAI29/9/20261/10/2026
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying…
Pendiente de análisisAlta (8.1)0.36%—HPE Networking Instant ONAI29/9/20261/10/2026
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to…
Pendiente de análisisCrítica (9.6)0.32%—HPE Instant ONAI29/9/20261/10/2026
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code…
Pendiente de análisisCrítica (9.6)1.0%—HPE Instant ONAI29/9/20261/10/2026
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on…
Orbitaley — Vulnerabilidades