Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.8%—HP Openview Client Configuraton ManagerHP Openview Configuration Management29/10/200716/6/2026
httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Configuration Manager (CCM) 2.0 allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories, as demonstrated by ~root.
ModificadaMedia (5.1)2.9%—Irfanview16/10/200716/6/2026
Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.
ModificadaMedia (6.8)30%💥 ExploitHP Openview OperationsHP Shared Trace Service9/8/200716/6/2026
Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests.
ModificadaAlta (8.5)8.9%💥 ExploitIrfanview30/4/200716/6/2026
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
ModificadaAlta (10)19%💥 ExploitGentoo Xnview24/4/200716/6/2026
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)8.3%💥 ExploitIrfanview11/4/200716/6/2026
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.
ModificadaAlta (10)7.9%💥 ExploitIrfanview4/4/200716/6/2026
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
ModificadaMedia (6.5)1.5%—HP Openview Network Node Manager28/3/200716/6/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
ModificadaMedia (4.3)1.2%—Irfanview3/3/200716/6/2026
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.
ModificadaMedia (6.8)0.37%—HP Openview Storage Data Protector9/2/200716/6/2026
Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.
ModificadaMedia (5.1)2.4%—HP Openview Network Node Manager23/1/200716/6/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.
ModificadaMedia (5)2.2%—HP Openview Network Node Manager12/1/200716/6/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.
ModificadaMedia (5)2.7%💥 ExploitNvidia Nview7/12/200616/6/2026
keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue crosses security boundaries. If not, then this is not a vulnerability.
ModificadaAlta (7.8)3.5%—HP Openview Client Configuraton Manager9/11/200616/6/2026
radexecd.exe in HP OpenView Client Configuraton Manager (CCM) does not require authentication before executing commands in the installation directory, which allows remote attackers to cause a denial of service (reboot) by calling radbootw.exe or create arbitrary files by calling radcrecv.
ModificadaBaja (2.6)2.7%💥 ExploitIrfanview26/8/200616/6/2026
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.
ModificadaBaja (2.6)1.3%—Irfanview18/8/200616/6/2026
IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.
ModificadaAlta (7.5)10%—HP Openview Storage Data Protector17/8/200616/6/2026
Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.
ModificadaAlta (7.5)6.2%—HP Openview Storage Data Protector24/5/200616/6/2026
Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)3.4%—HP Openview Network Node Manager24/5/200616/6/2026
Multiple unspecified vulnerabilities in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allow remote attackers to gain privileged access, execute arbitrary commands, or create arbitrary files via unknown vectors.
ModificadaAlta (7.2)0.42%—Gentoo NviewGentoo Xnview31/12/200516/6/2026
Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory.
ModificadaMedia (6.4)4.3%—HP Oracle FOR Openview31/12/200516/6/2026
Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.
AnalizadaCrítica (9.8)75%⚠ Explotación activa💥 ExploitHP Openview Network Node Manager2/9/200516/6/2026
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
ModificadaAlta (7.5)4.0%—HP Openview Network Node Manager3/5/200516/6/2026
Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.
ModificadaMedia (4.6)0.59%—HP Openview Event Correlation Services3/5/200516/6/2026
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
ModificadaAlta (7.5)5.6%💥 ExploitHP Openview Radia Management Portal3/5/200516/6/2026
Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.
Orbitaley — Vulnerabilidades