Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

362 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)80%💥 ExploitMicrofocus Secure Messaging Gateway29/6/201817/6/2026
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated…
ModificadaCrítica (9.8)81%💥 ExploitMicrofocus Secure Messaging Gateway29/6/201817/6/2026
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with…
ModificadaMedia (6.5)0.84%—Microfocus Solutions Business Manager22/6/201817/6/2026
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
ModificadaAlta (7.5)1.1%—Microfocus Solutions Business Manager21/6/201817/6/2026
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
ModificadaMedia (4.8)0.51%—Microfocus Solutions Business Manager21/6/201817/6/2026
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.
ModificadaMedia (6.1)0.65%—Microfocus Solutions Business Manager21/6/201817/6/2026
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
ModificadaCrítica (9.8)2.3%—Microfocus Solutions Business Manager21/6/201817/6/2026
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.
ModificadaAlta (8.8)0.58%—Microfocus CMS ServerMicrofocus Universal Cmbd Server16/6/201817/6/2026
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery…
ModificadaAlta (8.8)0.74%—Microfocus Universal Cmbd Browser16/6/201817/6/2026
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
ModificadaMedia (5.4)0.66%—Microfocus Universal CmdbMicrofocus Universal Cmdb BrowserMicrofocus CMS Server23/5/201817/6/2026
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site…
ModificadaMedia (5.4)1.2%—Microfocus Service Manager22/5/201817/6/2026
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
ModificadaAlta (7.8)0.37%—Microfocus Client21/5/201817/6/2026
The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.
ModificadaCrítica (9.8)0.99%—Microfocus Ucmdb Configuration Manager24/4/201817/6/2026
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
ModificadaMedia (5.3)0.54%—Microfocus Sentinel7/3/201817/6/2026
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is…
ModificadaCrítica (9.8)1.2%—Microfocus EdirectoryNetiq Edirectory2/3/201817/6/2026
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
ModificadaAlta (8.8)0.84%—Microfocus EdirectoryNetiq Edirectory2/3/201817/6/2026
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
ModificadaCrítica (9.8)1.2%—Microfocus Project AND Portfolio Management Center22/2/201817/6/2026
XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)
ModificadaCrítica (9.8)1.8%—Microfocus Ucmdb Configuration Manager22/2/201817/6/2026
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
ModificadaAlta (7.5)1.9%—Microfocus Universal Cmdb Foundation Software20/2/201817/6/2026
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.
ModificadaMedia (5.4)0.78%—Microfocus Project AND Portfolio Management15/2/201817/6/2026
A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.
ModificadaCrítica (9.8)1.2%—Microfocus Fortify Audit WorkbenchMicrofocus Fortify Software Security Center2/2/201817/6/2026
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.
ModificadaMedia (5.4)0.55%—Microfocus Operations Manager I21/12/201717/6/2026
Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
ModificadaAlta (7.3)0.50%—Microfocus Project AND Portfolio Management13/12/201717/6/2026
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.
ModificadaAlta (7.4)1.0%—Microfocus Project AND Portfolio Management13/12/201717/6/2026
Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Man-in-the-middle attack.
ModificadaAlta (7.8)1.6%💥 ExploitMicrofocus Connected Backup5/12/201717/6/2026
A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to allow escalation of privilege.
Orbitaley — Vulnerabilidades