Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Infocus Mondopad | 9/10/2017 | 17/6/2026 | InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file. | |
| Modificada | Media (5.5) | 0.86% | — | Infocuscorp Infocus Mondopad | 9/10/2017 | 17/6/2026 | Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scenario, the attacker provides an Excel spreadsheet, and the… | |
| Modificada | Media (5.3) | 0.75% | — | Microfocus Bi-directional Driver | 6/10/2017 | 17/6/2026 | The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes. | |
| Modificada | Alta (7.5) | 1.0% | — | Microfocus Bi-directional Driver | 6/10/2017 | 17/6/2026 | The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Visibroker | 21/9/2017 | 17/6/2026 | An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Visibroker | 21/9/2017 | 17/6/2026 | An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed. | |
| Modificada | Alta (7.5) | 1.0% | — | Microfocus Visibroker | 21/9/2017 | 17/6/2026 | An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of service. | |
| Modificada | Media (6.5) | 1.8% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 21/8/2017 | 17/6/2026 | A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured. Note… | |
| Modificada | Alta (8.8) | 0.75% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 21/8/2017 | 17/6/2026 | A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new… | |
| Modificada | Media (5.4) | 0.97% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 21/8/2017 | 17/6/2026 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security… | |
| Modificada | Media (6.1) | 1.3% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2… | |
| Modificada | Crítica (9.8) | 2.4% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration… | |
| Modificada | Alta (8.8) | 0.75% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter… | |
| Modificada | Media (6.5) | 1.4% | — | Micro Focus Vibe | 18/5/2017 | 17/6/2026 | An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is… | |
| Modificada | Alta (7.5) | 1.7% | — | Microfocus Sentinel | 30/3/2017 | 17/6/2026 | A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service. | |
| Modificada | Media (5.3) | 1.0% | — | Microfocus Sentinel | 30/3/2017 | 17/6/2026 | A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration). | |
| Modificada | Media (6.5) | 2.2% | — | Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE | 29/11/2016 | 17/6/2026 | Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.… | |
| Modificada | Crítica (9.8) | 2.8% | — | Microfocus Rumba | 4/11/2016 | 17/6/2026 | Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers able to inject arguments to these binaries to execute code. | |
| Modificada | Alta (8.8) | 7.8% | 💥 Exploit | Microfocus Rumba FTP | 27/10/2016 | 17/6/2026 | Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious server. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Microfocus Rumba | 3/7/2016 | 17/6/2026 | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a… | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Microfocus Rumba | 3/7/2016 | 17/6/2026 | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (2) the CPName property value to ObjectXSNAConfig.ObjectXSNAConfig in… | |
| Modificada | Media (6.1) | 1.4% | — | Microfocus Self Service Password Reset | 24/3/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (8) | 1.6% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors. | |
| Modificada | Alta (7.8) | 0.40% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. |