Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

354 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.0%—IBM Marketing PlatformIBM Marketing OperationsIBM Distributed Marketing22/5/201717/6/2026
IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282.
ModificadaAlta (7.5)13%—OpensslHP Operations Agent4/5/201717/6/2026
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
ModificadaAlta (7.5)55%💥 ExploitOpensslOracle Agile Engineering Data ManagementOracle Communications Application Session ControllerOracle Communications Eagle LNP Application Processor+34/5/201717/6/2026
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
ModificadaAlta (7)0.34%—EMC RSA Archer Security Operations Management29/3/201717/6/2026
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.
ModificadaAlta (7.5)1.5%—Dell VCE Vision Intelligent Operations21/2/201717/6/2026
The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.
ModificadaMedia (6.7)0.27%—Dell VCE Vision Intelligent Operations21/2/201717/6/2026
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
ModificadaAlta (8.5)2.0%—Vmware Vrealize Operations29/12/201617/6/2026
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
ModificadaCrítica (10)3.2%—Vmware Vrealize Operations29/12/201617/6/2026
VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.
ModificadaCrítica (9.8)11%—Redhat Jboss Operations Network27/9/201617/6/2026
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaCrítica (9.8)1.0%—Pivotal Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
ModificadaCrítica (9.8)1.5%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.
ModificadaCrítica (9.8)0.90%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
ModificadaMedia (5.4)0.84%—HP Operations Manager8/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)2.1%—Redhat Jboss Operations Network7/9/201617/6/2026
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.
ModificadaCrítica (9.8)6.8%—Redhat Jboss Operations Network2/8/201617/6/2026
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
ModificadaCrítica (9.8)4.4%—HP Operations Manager1/8/201617/6/2026
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ModificadaMedia (6.5)2.7%—Oracle Communications Operations Monitor21/7/201617/6/2026
Unspecified vulnerability in the Oracle Communications Operations Monitor component in Oracle Communications Applications before 3.3.92.0.0 allows remote authenticated users to affect confidentiality via vectors related to Infrastructure.
ModificadaCrítica (9.8)6.7%—HP Operations OrchestrationHP Operations Orchestration Content22/3/201617/6/2026
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ModificadaAlta (7.2)13%💥 ExploitSchneider-electric Struxureware Building Operations Automation Server AS FirmwareSchneider-electric Struxureware Building Operations Automation Server As-p Firmware2/3/201617/6/2026
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
ModificadaCrítica (10)6.6%—HP Operations Manager30/1/201617/6/2026
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ModificadaMedia (6.8)1.5%—HP Operations Orchestration23/11/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (10)9.6%—HP Operations Manager I22/8/201517/6/2026
Unspecified vulnerability in HP Operations Manager i (OMi) 9.22, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.4)0.34%—HP Operations Manager I22/8/201517/6/2026
Unspecified vulnerability in the execve system-call implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.
ModificadaMedia (4.9)1.6%—Views Bulk Operations Project Views Bulk Operations18/8/201517/6/2026
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
ModificadaMedia (4.3)8.8%—Microsoft System Center Operations Manager15/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "System Center Operations Manager Web Console XSS Vulnerability."
Orbitaley — Vulnerabilidades