Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

482 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.6%—HP Insight Control Performance Management3/5/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (6)1.8%—HP Insight Control Performance Management3/5/201116/6/2026
Unspecified vulnerability in HP Insight Control Performance Management before 6.3 allows remote authenticated users to gain privileges via unknown vectors.
ModificadaMedia (5)2.2%—HP Performance Insight29/4/201116/6/2026
Unspecified vulnerability in HP Performance Insight 5.0, 5.1x. 5.2x, 5.3x, 5.4, 5.41, and 5.41.002 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaAlta (10)6.8%—BMC Performance Analysis FOR ServersBMC Performance Assurance FOR ServersBMC Performance Assurance FOR Virtual ServersBMC Performance Analyzer FOR Servers+210/2/201116/6/2026
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management…
ModificadaAlta (10)82%💥 ExploitHP Openview Performance Insight2/2/201116/6/2026
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.
ModificadaMedia (5)2.2%—HP Insight Control Performance Management2/11/201016/6/2026
Unspecified vulnerability in HP Insight Control Performance Management before 6.1 update 2 allows remote attackers to read arbitrary files via unknown vectors.
ModificadaMedia (6.8)0.97%—HP Insight Control Performance Management2/11/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (8)2.4%—HP Insight Control Performance Management2/11/201016/6/2026
Unspecified vulnerability in HP Insight Control Performance Management before 6.2 allows remote authenticated users to gain privileges via unknown vectors.
ModificadaMedia (4.3)1.7%—HP Insight Control Performance Management2/11/201016/6/2026
Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)4.5%—Tibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Service Performance Manager26/10/201016/6/2026
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections,…
ModificadaAlta (10)78%💥 ExploitHP LoadrunnerHP Performance Center7/5/201016/6/2026
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.3)1.4%—Hitachi JP1 Integrated Management Service SupportHitachi Jp1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/integrated Management-view+1021/4/201016/6/2026
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
ModificadaAlta (10)5.3%—HP Openview Performance Insight10/3/201016/6/2026
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.
ModificadaBaja (2.6)1.0%—CA Ehealth Performance Manager24/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.
ModificadaAlta (10)8.5%—Ciscoworks Internetwork Performance Monitor21/1/201016/6/2026
Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party…
ModificadaAlta (7.8)1.7%—HP Performance Insight8/9/200916/6/2026
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco…
ModificadaAlta (10)3.6%—HP Performance Insight8/9/200916/6/2026
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a "Remote exploit" on Windows platforms, and (2) a "Remote preauthentication exploit" on the Windows Server 2003 SP2 platform, as demonstrated by certain modules in VulnDisco Pack…
ModificadaAlta (9.3)5.7%—HP Openview Performance AgentInnermedia Dynazip MAXInnermedia Dynazip MAX SecureFilestream Turbozip13/4/200916/6/2026
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code…
ModificadaMedia (4.3)3.1%—HP Openview Performance AgentHP Openview ReporterHP Performance AgentHP Reporter23/10/200816/6/2026
The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages)…
ModificadaAlta (9)1.6%—Jdedwards EnterpriseoneOracle Peoplesoft HCM Eperformance16/4/200816/6/2026
Unspecified vulnerability in the PeopleSoft HCM ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 and 9.0 has unknown impact and remote attack vectors, aka PSE03.
ModificadaAlta (10)21%—Ciscoworks Internetwork Performance Monitor14/3/200816/6/2026
Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands.
ModificadaAlta (9.3)24%—Broadcom Advantage Data TransportBroadcom Brightstor PortalBroadcom Brightstor SAN ManagerBroadcom Cleverpath Aion+2026/7/200716/6/2026
Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain…
ModificadaAlta (7.5)4.0%—BMC Performance Manager22/4/200716/6/2026
PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this…
ModificadaAlta (10)45%—HP Mercury Loadrunner AgentHP Mercury Monitor Over FirewallHP Mercury Performance Center Agent8/2/200716/6/2026
Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in…
ModificadaMedia (5)1.6%—Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+527/4/200616/6/2026
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.
Orbitaley — Vulnerabilidades