Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure. | |
| Modificada | Alta (8.8) | 1.2% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to private data. | |
| Modificada | Alta (7.8) | 7.8% | 💥 Exploit | Microfocus Data Protector | 13/9/2019 | 17/6/2026 | Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges. | |
| Modificada | Alta (7.5) | 0.87% | — | Microfocus Service Manager | 10/9/2019 | 17/6/2026 | Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized modification of data. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service ManagerMicrofocus Service Manager Chat ServerMicrofocus Service Manager Chat Service | 10/9/2019 | 17/6/2026 | HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. | |
| Modificada | Media (4.3) | 0.69% | — | Microfocus Content Manager | 30/8/2019 | 17/6/2026 | Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state. | |
| Modificada | Alta (7.5) | 2.6% | — | Microfocus Verastream Host Integrator | 23/8/2019 | 17/6/2026 | Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files. | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Netiq Self Service Password Reset | 14/8/2019 | 17/6/2026 | A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate. | |
| Modificada | Media (5.4) | 0.78% | — | Microfocus Content Manager | 7/8/2019 | 17/6/2026 | Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request. | |
| Modificada | Media (5.9) | 0.82% | — | Microfocus Netiq Advanced Authentication | 10/7/2019 | 17/6/2026 | A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack. | |
| Modificada | Media (5.4) | 0.62% | — | Microfocus Fortify Software Security Center | 19/6/2019 | 17/6/2026 | Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute… | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Solutions Business Manager | 7/6/2019 | 17/6/2026 | Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect. | |
| Modificada | Alta (8.8) | 2.5% | — | Microfocus Service Manager | 3/6/2019 | 17/6/2026 | Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61. This vulnerability could allow Remote unauthorized command execution and unauthorized disclosure of information. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Identity Manager | 9/5/2019 | 17/6/2026 | The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability. | |
| Modificada | Media (6.1) | 1.0% | — | Microfocus Open Enterprise Server | 2/5/2019 | 17/6/2026 | A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older… | |
| Modificada | Crítica (9.8) | 7.0% | — | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Modificada | Alta (8.8) | 1.8% | — | Microfocus Network AutomationMicrofocus Network Operations Management | 29/4/2019 | 17/6/2026 | A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution. | |
| Modificada | Alta (7.5) | 1.7% | — | Microfocus Content Manager | 1/4/2019 | 17/6/2026 | An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the… | |
| Modificada | Media (6.1) | 0.51% | — | Microfocus Solutions Business Manager | 27/3/2019 | 17/6/2026 | Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. | |
| Modificada | Alta (7.5) | 0.80% | — | Microfocus Solutions Business Manager | 27/3/2019 | 17/6/2026 | Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. | |
| Modificada | Alta (7.5) | 0.70% | — | Microfocus Solutions Business Manager | 27/3/2019 | 17/6/2026 | Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. | |
| Modificada | Crítica (9.8) | 1.5% | — | Microfocus Solutions Business Manager | 27/3/2019 | 17/6/2026 | Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. |