Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—HPE Nimbleos7/11/201917/6/2026
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this…
ModificadaCrítica (9.8)1.4%—HPE Smart Update Manager5/6/201917/6/2026
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
ModificadaAlta (7.8)0.32%—HPE Smart Update Manager5/6/201917/6/2026
A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege.
ModificadaAlta (7.5)5.7%💥 PoCNetapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+215/5/201917/6/2026
NTP through 4.2.8p12 has a NULL Pointer Dereference.
ModificadaMedia (5.3)9.4%—LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+284/2/201917/6/2026
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
ModificadaMedia (5.9)0.66%—HPE Service Governance Framework17/10/201817/6/2026
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.
ModificadaMedia (5.9)2.5%—HPE Storageworks XP7 Automation Director27/9/201817/6/2026
HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific conditions when running a service template.
ModificadaAlta (8.8)0.88%—HPE Device Entitlement Gateway27/9/201817/6/2026
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.
ModificadaMedia (5.5)0.36%—HPE 3par Service Provider14/8/201817/6/2026
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to allow disclosure of privileged information.
ModificadaAlta (7.5)3.6%—HPE Arubaos6/8/201817/6/2026
Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the ability to execute arbitrary code - remote code execution has not yet been confirmed.
ModificadaMedia (5.9)3.9%—NTPFreebsdHPE Hpux-ntpSiemens Simatic NET CP 443-1 OPC UA Firmware4/6/201817/6/2026
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2)…
ModificadaAlta (7.5)9.0%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+126/3/201817/6/2026
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
ModificadaMedia (5.3)2.7%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+56/3/201817/6/2026
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for…
AnalizadaCrítica (9.8)92%⚠ Explotación activa💥 ExploitHPE Proliant Ml10 Gen9 Server FirmwareSiemens Simatic Itp1000 FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc847c Firmware+322/5/201717/6/2026
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel…
ModificadaAlta (8.8)6.5%—NTPHPE Hpux-ntpApple MAC OS XSiemens Simatic NET CP 443-1 OPC UA Firmware27/3/201717/6/2026
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
ModificadaAlta (7.5)53%💥 ExploitNTPHPE Hpux-ntp13/1/201717/6/2026
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
ModificadaAlta (7.5)12%—NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+513/1/201717/6/2026
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
ModificadaAlta (8.8)2.3%—HPE Project AND Portfolio Management Center9/6/201617/6/2026
HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors.
ModificadaAlta (7.2)0.39%—HPE Smart Update Manager10/12/201417/6/2026
Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors.
ModificadaAlta (7.5)1.5%—Owncloud ServerPhpexcel Project Phpexcel4/6/201417/6/2026
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
ModificadaAlta (10)4.1%💥 ExploitPhpenter PHP Enter27/11/201216/6/2026
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.
ModificadaMedia (5)1.2%—Bishop Bettini Phpesp24/9/201116/6/2026
php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files.
ModificadaMedia (4.3)1.5%💥 ExploitGlarotech Phpeppershop13/4/201016/6/2026
Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.
ModificadaMedia (5)1.1%—Phpee Pphlogger10/12/200916/6/2026
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error…
ModificadaMedia (4.3)1.5%💥 ExploitPhpee Pphlogger10/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.