Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.7%—HPE Arubaos-cx2/3/202217/6/2026
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s):…
ModificadaAlta (8.8)2.6%—HPE Arubaos-cx2/3/202217/6/2026
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s):…
ModificadaMedia (5.3)0.69%—HPE Integrated Lights-out24/2/202217/6/2026
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an…
ModificadaMedia (6.1)0.73%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaMedia (6.1)0.56%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaAlta (7.8)0.23%—HPE Flexnetwork 5130 Jg932a FirmwareHPE Flexnetwork 5130 Jg933a FirmwareHPE Flexnetwork 5130 Jg934a FirmwareHPE Flexnetwork 5130 Jg936a Firmware+34/2/202217/6/2026
A potential local buffer overflow vulnerability has been identified in HPE FlexNetwork 5130 EL Switch Series version: Prior to 5130_EI_7.10.R3507P02. HPE has made the following software update to resolve the vulnerability in HPE FlexNetwork 5130 EL Switch Series version 5130_EL_7.10.R3507P02.
ModificadaMedia (6.7)0.24%—HPE Agentless ManagementHPE Proliant Agentless Management4/2/202217/6/2026
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and…
ModificadaCrítica (9.8)1.2%—HPE TEZ18/1/202217/6/2026
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9: mapr-tez-0.9.201907090334-1.noarch; prior to Tez-0.9.2:…
ModificadaAlta (7.8)0.24%—IBM MQ FOR HPE Nonstop14/12/202117/6/2026
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaMedia (6.7)0.29%—HPE Proliant Microserver Gen10 Plus FirmwareHPE Proliant Ml30 Gen10 Server FirmwareHPE Proliant Dl20 Gen10 Server Firmware1/11/202117/6/2026
A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs prior to version 2.52. The vulnerability could be locally exploited to cause disclosure of sensitive information, denial…
ModificadaMedia (6.1)0.55%—HPE Superdome Flex FirmwareHPE Superdome Flex 280 Firmware19/10/202117/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex…
ModificadaCrítica (9.8)1.8%—HPE 3par OSHPE Primera 630 FirmwareHPE Primera 650 FirmwareHPE Primera 670 Firmware+211/10/202117/6/2026
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity,…
ModificadaMedia (6.5)0.50%—HPE Storeonce 5200 FirmwareHPE Storeonce 5650 FirmwareHPE Storeonce 5250 FirmwareHPE Storeonce 3640 Firmware+227/9/202117/6/2026
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce…
ModificadaAlta (8.1)0.90%—HPE Backbox H4.09 FirmwareEtinet Backbox E4.09 Firmware25/6/202117/6/2026
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that the user is not running the XYGate…
ModificadaMedia (5.5)0.23%—HPE Oneview Global Dashboard24/6/202117/6/2026
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.
ModificadaMedia (6.5)0.84%—HPE Superdome Flex Server Firmware1/4/202117/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following…
ModificadaMedia (6.1)0.62%—HPE Integrated Lights-out Amplifier1/4/202117/6/2026
A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amplifier Pack: HPE iLO Amplifier Pack 1.95 or later.
ModificadaMedia (5.5)0.21%—HPE Unified Data Management30/3/202117/6/2026
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM). Version 1.2103.0 of HPE Unified Data…
ModificadaAlta (7.5)1.0%—HPE Network Orchestrator22/3/202117/6/2026
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.
ModificadaAlta (8.8)3.6%—HPE WEB Viewpoint9/2/202117/6/2026
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AAR through T0952L01^AAX, and T0986L01^AAD through T0986L01^AAJ (L) and T0320H01^ABW through T0320H01^ACC, T0952H01^AAQ through T0952H01^AAW, and T0986H01^AAC through…
ModificadaMedia (5.9)1.4%—HPE WEB Viewpoint9/2/202117/6/2026
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ,…
ModificadaMedia (4.4)0.30%—Arubanetworks Aruba 5406r ZL2 FirmwareArubanetworks Aruba 5412r ZL2 FirmwareArubanetworks Aruba 3810m FirmwareArubanetworks Aruba 2930m Firmware+119/2/202117/6/2026
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a…
ModificadaAlta (7.8)0.84%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
ModificadaAlta (7.8)0.38%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.
Orbitaley — Vulnerabilidades