Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | HPE Nimbleos | 7/11/2019 | 17/6/2026 | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this… | |
| Modificada | Crítica (9.8) | 1.4% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5. | |
| Modificada | Alta (7.8) | 0.32% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege. | |
| Modificada | Alta (7.5) | 5.7% | 💥 PoC | Netapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+2 | 15/5/2019 | 17/6/2026 | NTP through 4.2.8p12 has a NULL Pointer Dereference. | |
| Modificada | Media (5.3) | 9.4% | — | LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+28 | 4/2/2019 | 17/6/2026 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| Modificada | Media (5.9) | 0.66% | — | HPE Service Governance Framework | 17/10/2018 | 17/6/2026 | A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler. | |
| Modificada | Media (5.9) | 2.5% | — | HPE Storageworks XP7 Automation Director | 27/9/2018 | 17/6/2026 | HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific conditions when running a service template. | |
| Modificada | Alta (8.8) | 0.88% | — | HPE Device Entitlement Gateway | 27/9/2018 | 17/6/2026 | A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege. | |
| Modificada | Media (5.5) | 0.36% | — | HPE 3par Service Provider | 14/8/2018 | 17/6/2026 | A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to allow disclosure of privileged information. | |
| Modificada | Alta (7.5) | 3.6% | — | HPE Arubaos | 6/8/2018 | 17/6/2026 | Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the ability to execute arbitrary code - remote code execution has not yet been confirmed. | |
| Modificada | Media (5.9) | 3.9% | — | NTPFreebsdHPE Hpux-ntpSiemens Simatic NET CP 443-1 OPC UA Firmware | 4/6/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2)… | |
| Modificada | Alta (7.5) | 9.0% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+12 | 6/3/2018 | 17/6/2026 | The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association. | |
| Modificada | Media (5.3) | 2.7% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+5 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa💥 Exploit | HPE Proliant Ml10 Gen9 Server FirmwareSiemens Simatic Itp1000 FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc847c Firmware+32 | 2/5/2017 | 17/6/2026 | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel… | |
| Modificada | Alta (8.8) | 6.5% | — | NTPHPE Hpux-ntpApple MAC OS XSiemens Simatic NET CP 443-1 OPC UA Firmware | 27/3/2017 | 17/6/2026 | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable. | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | NTPHPE Hpux-ntp | 13/1/2017 | 17/6/2026 | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. | |
| Modificada | Alta (7.5) | 12% | — | NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 13/1/2017 | 17/6/2026 | NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address. | |
| Modificada | Alta (8.8) | 2.3% | — | HPE Project AND Portfolio Management Center | 9/6/2016 | 17/6/2026 | HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.39% | — | HPE Smart Update Manager | 10/12/2014 | 17/6/2026 | Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Owncloud ServerPhpexcel Project Phpexcel | 4/6/2014 | 17/6/2026 | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Phpenter PHP Enter | 27/11/2012 | 16/6/2026 | Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter. | |
| Modificada | Media (5) | 1.2% | — | Bishop Bettini Phpesp | 24/9/2011 | 16/6/2026 | php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Glarotech Phpeppershop | 13/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter. | |
| Modificada | Media (5) | 1.1% | — | Phpee Pphlogger | 10/12/2009 | 16/6/2026 | PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpee Pphlogger | 10/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter. |