Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.00%—Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager30/8/202117/6/2026
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.
ModificadaMedia (4.9)1.1%—Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager30/8/202117/6/2026
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.
ModificadaMedia (6.5)69%💥 ExploitVmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager31/3/202112/8/2026
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
AnalizadaAlta (7.5)78%⚠ Explotación activa💥 ExploitVmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager31/3/20212/10/2026
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
ModificadaAlta (8.8)2.0%—Microsoft System Center Operations Manager25/2/202117/6/2026
System Center Operations Manager Elevation of Privilege Vulnerability
ModificadaAlta (8.8)0.45%—Veritas InfoscaleVeritas Infoscale Operations ManagerVeritas Storage FoundationVeritas Storage Foundation AND High Availability6/1/202117/6/2026
An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl.…
ModificadaMedia (5.7)0.71%—Vmware Tanzu Application Service FOR Virtual MachinesVmware Operations Manager31/7/202017/6/2026
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to…
ModificadaMedia (5.4)1.3%—Microsoft System Center Operations Manager9/6/202017/6/2026
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.
ModificadaMedia (6.5)1.1%—Pivotal Software Operations Manager9/1/202017/6/2026
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
ModificadaAlta (7.5)1.1%—Pivotal Software Application ServicePivotal Software Cloud Foundry UAAPivotal Software Operations Manager5/8/201917/6/2026
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
ModificadaMedia (5.4)0.65%—Pivotal Software Operations Manager6/6/201917/6/2026
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have…
ModificadaMedia (5.4)0.85%—Pivotal Software Operations Manager7/3/201917/6/2026
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could…
ModificadaAlta (8.8)1.1%—Pivotal Software Operations Manager2/11/201817/6/2026
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator…
ModificadaAlta (8.8)1.4%—Pivotal Software Operations Manager5/10/201817/6/2026
Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can…
ModificadaMedia (5.9)0.86%—Pivotal Software Operations Manager11/7/201817/6/2026
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the…
ModificadaMedia (6.5)0.89%—Pivotal Software Operations Manager25/6/201817/6/2026
Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities may be able to impact Operations Manager
ModificadaMedia (5.4)0.55%—Microfocus Operations Manager I21/12/201717/6/2026
Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
ModificadaCrítica (9.8)1.0%—Pivotal Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
ModificadaCrítica (9.8)1.5%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.
ModificadaCrítica (9.8)0.90%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
ModificadaMedia (5.4)0.84%—HP Operations Manager8/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)4.4%—HP Operations Manager1/8/201617/6/2026
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ModificadaCrítica (10)6.6%—HP Operations Manager30/1/201617/6/2026
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ModificadaAlta (10)9.6%—HP Operations Manager I22/8/201517/6/2026
Unspecified vulnerability in HP Operations Manager i (OMi) 9.22, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.4)0.34%—HP Operations Manager I22/8/201517/6/2026
Unspecified vulnerability in the execve system-call implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.
Orbitaley — Vulnerabilidades