Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 8.2% | — | HP Data Protector Media Operations | 3/2/2012 | 16/6/2026 | DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field. | |
| Modificada | Media (4.3) | 1.1% | — | Hitachi IT Operations Director | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Director 02-50-01 through 02-50-07, 03-00 through 03-00-04, and possibly other versions before 03-00-06, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Hitachi IT Operations Analyzer | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Analyzer 02-01, 02-51 through 02-51-01, and 02-53 through 02-53-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Redhat Jboss Operations NetworkRhq-project RHQ | 8/1/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.2) | 0.33% | — | HP Operations AgentHP Performance Agent | 24/11/2011 | 16/6/2026 | Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors. | |
| Modificada | Alta (10) | 11% | — | Cisco Unified Service MonitorCiscoworks LAN Management SolutionCisco Unified Operations ManagerEMC Ionix ACM+2 | 19/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for… | |
| Modificada | Media (6.4) | 4.8% | — | HP Openview Performance AgentHP Operations Agent | 1/7/2011 | 16/6/2026 | ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command. | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716. | |
| Modificada | Media (4.3) | 21% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to… | |
| Modificada | Media (5.5) | 1.2% | — | HP Operations | 4/4/2011 | 16/6/2026 | Unspecified vulnerability in HP Operations 9.10 on UNIX platforms allows remote authenticated users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Media (4.3) | 1.8% | — | HP Operations | 4/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Operations 9.10 on UNIX platforms allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 6.0% | — | Ciscoworks Common ServicesCiscoworks LAN Management SolutionCisco QOS Policy ManagerCisco Security Manager+3 | 29/10/2010 | 16/6/2026 | Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352. | |
| Modificada | Media (4.3) | 2.0% | — | HP Operations Orchestration | 26/10/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.28% | — | HP Operations Agent | 8/9/2010 | 16/6/2026 | Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (7.5) | 5.3% | — | HP Operations Agent | 8/9/2010 | 16/6/2026 | Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | HP Operations Manager | 21/4/2010 | 16/6/2026 | Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll. | |
| Modificada | Alta (10) | 8.6% | — | HP Operations Agent | 9/2/2010 | 16/6/2026 | HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 11% | — | Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+19 | 11/12/2009 | 16/6/2026 | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)… | |
| Modificada | Alta (10) | 79% | 💥 Exploit | HP Operations Manager | 3/12/2009 | 16/6/2026 | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap… | |
| Modificada | Alta (10) | 69% | 💥 Exploit | HP Operations Dashboard | 3/12/2009 | 16/6/2026 | HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap… | |
| Modificada | Alta (10) | 79% | 💥 Exploit | HP Operations Manager | 24/11/2009 | 16/6/2026 | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to… | |
| Modificada | Alta (10) | 9.6% | 💥 Exploit | HP Operations Manager | 8/9/2009 | 16/6/2026 | Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2007-3872. NOTE: as of 20090903, this… | |
| Modificada | Alta (10) | 4.6% | — | HP Operations Dashboard | 8/9/2009 | 16/6/2026 | Unspecified vulnerability in the Portal in HP Operations Dashboard 2.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable… | |
| Modificada | Alta (7.5) | 2.2% | — | Karim Ratib Views Bulk Operations | 27/6/2009 | 16/6/2026 | Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions). |