Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.0%—HP Network Operations Management UltimateHP Network Automation22/5/201817/6/2026
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.
ModificadaMedia (6.1)1.6%—HP Network Operations Management UltimateHP Network Automation22/5/201817/6/2026
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting,…
ModificadaCrítica (9.8)8.7%—HP Network Automation15/2/201817/6/2026
A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
ModificadaMedia (6.3)1.9%—HP Network Automation15/2/201817/6/2026
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
ModificadaAlta (7.5)5.3%—HP Network Automation15/2/201817/6/2026
A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
ModificadaAlta (7.5)17%—HP Network Automation15/2/201817/6/2026
A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
ModificadaCrítica (9.8)4.7%—HP Network Automation15/2/201817/6/2026
A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
ModificadaCrítica (9.8)15%—HP Network Automation15/2/201817/6/2026
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.
ModificadaAlta (7.8)0.50%—HP Network Automation29/9/201617/6/2026
HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.
ModificadaAlta (7.3)4.4%—HP Network Automation29/9/201617/6/2026
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
ModificadaAlta (8.2)1.1%—Cisco Cloud Network Automation Provisioner3/7/201617/6/2026
Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID CSCuy77145.
ModificadaAlta (7.1)0.86%—Cisco Cloud Network Automation Provisioner12/5/201617/6/2026
SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175.
ModificadaCrítica (9.8)11%—HP Network Automation15/3/201617/6/2026
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988.
ModificadaCrítica (9.8)11%—HP Network Automation15/3/201617/6/2026
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.
ModificadaAlta (7.2)0.62%—HP Network Automation10/10/201417/6/2026
Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.
ModificadaAlta (9.3)9.0%—HP Network Automation2/2/201216/6/2026
Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (6.5)2.0%💥 ExploitHP Network Automation1/8/201116/6/2026
SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)3.1%—HP Network Automation1/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)2.4%—HP Network Automation27/4/201116/6/2026
Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaBaja (2.1)0.34%—Opsware Network Automation System27/7/200616/6/2026
Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.