Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.22% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has… | |
| Modificada | Alta (7.3) | 0.21% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to read and write to the iLO 5 firmware file system resulting in… | |
| Modificada | Alta (8.8) | 0.43% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an… | |
| Modificada | Alta (8.8) | 0.43% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an… | |
| Modificada | Alta (7.3) | 0.24% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality and integrity, and a partial loss of… | |
| Modificada | Alta (7.8) | 0.22% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has… | |
| Modificada | Alta (8.4) | 0.23% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided… | |
| Modificada | Alta (8.4) | 0.23% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided… | |
| Modificada | Media (6.7) | 0.22% | — | HPE Integrated Lights-out 5 Firmware | 12/8/2022 | 17/6/2026 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has… | |
| Modificada | Media (4.8) | 0.43% | — | HPE Flexnetwork 5130 EI FirmwareHPE Flexfabric 5945 Firmware | 8/7/2022 | 17/6/2026 | A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE… | |
| Modificada | Crítica (9.8) | 0.90% | — | HPE Icewall SSO Certd | 8/7/2022 | 17/6/2026 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd… | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins HPE Network Virtualization | 30/6/2022 | 17/6/2026 | Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 1.3% | — | HPE Nonstop Distributed Systems Management / Software Configuration Manager | 28/6/2022 | 17/6/2026 | A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM. | |
| Modificada | Alta (7.5) | 0.80% | — | HPE Storeonce 3640 Firmware | 27/6/2022 | 17/6/2026 | A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce Software 4.3.2. | |
| Modificada | Crítica (9.8) | 1.5% | — | HPE Slingshot FirmwareHPE Cray EX Supercomputers FirmwareHPE Cray SH Supercomputer AIR Cooled Base System Code FirmwareHPE Cray SH Supercomputer Liquid Cooled Base System Code Firmware+1 | 24/6/2022 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX… | |
| Modificada | Alta (7.8) | 0.23% | — | HPE Control Repository Manager | 24/6/2022 | 17/6/2026 | A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control Repository Manager installer 7.6.14.0. | |
| Modificada | Crítica (9.8) | 1.8% | — | HPE Nimbleos | 20/5/2022 | 17/6/2026 | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to… | |
| Modificada | Media (5.5) | 0.23% | — | IBM MQ FOR HPE Nonstop | 13/5/2022 | 17/6/2026 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853. | |
| Modificada | Alta (7.5) | 1.1% | — | HPE Nimbleos | 9/5/2022 | 17/6/2026 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software… | |
| Modificada | Alta (7.5) | 0.80% | — | HPE Nimbleos | 12/4/2022 | 17/6/2026 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for software updates initiated by the Nimble… | |
| Modificada | Media (6.7) | 0.24% | — | HPE Superdome Flex Server FirmwareHPE Superdome Flex 280 Server Firmware | 12/4/2022 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally exploited to allow an user with Administrator access to escalate their privilege. The vulnerability is resolved in the latest firmware update. HPE Superdome Flex Server… | |
| Modificada | Media (6.5) | 0.82% | — | HPE Aruba Instant ON 1930 8G 2sfp FirmwareHPE Aruba Instant ON 1930 8G Class4 POE 2sfp 124w FirmwareHPE Aruba Instant ON 1930 48G Class4 POE 4sfp/sfp+ 370w FirmwareHPE Aruba Instant ON 1930 48G 4sfp/sfp+ Firmware+3 | 12/4/2022 | 17/6/2026 | A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | |
| Modificada | Alta (7.5) | 0.95% | — | HPE Aruba Instant ON 1930 8G 2sfp FirmwareHPE Aruba Instant ON 1930 8G Class4 POE 2sfp 124w FirmwareHPE Aruba Instant ON 1930 48G Class4 POE 4sfp/sfp+ 370w FirmwareHPE Aruba Instant ON 1930 48G 4sfp/sfp+ Firmware+3 | 12/4/2022 | 17/6/2026 | A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | |
| Modificada | Media (6.1) | 0.79% | — | HPE Arubaos-cx | 2/3/2022 | 17/6/2026 | Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX… | |
| Modificada | Alta (8.1) | 0.98% | — | HPE Arubaos-cx | 2/3/2022 | 17/6/2026 | Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s):… |