Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Microfocus Operation Bridge ManagerMicrofocus Operations Bridge ManagerHP Universal Cmbd FoundationMicrofocus Application Performance Management+3 | 22/10/2020 | 17/6/2026 | Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP… | |
| Modificada | Baja (3.3) | 0.32% | — | IBM Tivoli Business Service Manager | 15/9/2020 | 17/6/2026 | IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247. | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Media (5.3) | 1.8% | — | Intel Active Management Technology FirmwareIntel Service Manager | 15/6/2020 | 17/6/2026 | Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.5) | 2.2% | — | Intel Active Management Technology FirmwareIntel Service Manager | 15/6/2020 | 17/6/2026 | Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Crítica (9.8) | 3.4% | — | Intel Active Management Technology FirmwareIntel Service Manager | 15/6/2020 | 17/6/2026 | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Crítica (9.8) | 3.5% | — | Intel Active Management Technology FirmwareIntel Service Manager | 15/6/2020 | 17/6/2026 | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (6.1) | 0.77% | — | Microfocus Service Manager | 19/5/2020 | 17/6/2026 | Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (8.8) | 1.1% | — | Microfocus Service Manager Automation | 26/3/2020 | 17/6/2026 | An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL… | |
| Modificada | Media (5.3) | 0.86% | — | Microfocus Service Manager | 16/3/2020 | 17/6/2026 | Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data. | |
| Modificada | Media (5.3) | 0.86% | — | Microfocus Service Manager | 16/3/2020 | 17/6/2026 | HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data. | |
| Modificada | Media (5.4) | 0.48% | — | Microfocus Service Manager | 9/3/2020 | 17/6/2026 | There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks. | |
| Modificada | Media (6.5) | 0.53% | — | Microfocus Service Manager | 18/9/2019 | 17/6/2026 | Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure. | |
| Modificada | Media (6.5) | 0.48% | — | Microfocus Service Manager | 18/9/2019 | 17/6/2026 | Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure. | |
| Modificada | Media (4.3) | 0.68% | — | Microfocus Service Manager | 18/9/2019 | 17/6/2026 | Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited in some special cases to allow information exposure through an error message. | |
| Modificada | Alta (8.3) | 0.99% | — | Microfocus Service Manager | 18/9/2019 | 17/6/2026 | Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized access and modification of data. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure. | |
| Modificada | Alta (8.8) | 1.2% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service Manager | 17/9/2019 | 17/6/2026 | Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to private data. | |
| Modificada | Alta (7.5) | 0.87% | — | Microfocus Service Manager | 10/9/2019 | 17/6/2026 | Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized modification of data. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service ManagerMicrofocus Service Manager Chat ServerMicrofocus Service Manager Chat Service | 10/9/2019 | 17/6/2026 | HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. | |
| Modificada | Alta (8.8) | 2.5% | — | Microfocus Service Manager | 3/6/2019 | 17/6/2026 | Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61. This vulnerability could allow Remote unauthorized command execution and unauthorized disclosure of information. | |
| Modificada | Media (6.5) | 0.60% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate. | |
| Modificada | Alta (8.8) | 1.9% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.7% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors. |