Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway | 11/9/2019 | 17/6/2026 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning proxies. | |
| Modificada | Alta (7.5) | 2.4% | — | Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway | 11/9/2019 | 17/6/2026 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies. | |
| Modificada | Alta (8.8) | 1.7% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Media (6.5) | 1.2% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters. | |
| Modificada | Alta (8.8) | 0.98% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control. | |
| Modificada | Media (5.4) | 0.97% | — | Tridium NiagaraTridium Niagara AX FrameworkTridium Niagara Enterprise Security | 29/1/2019 | 17/6/2026 | Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all versions prior to 4.6.96.28.4 a cross-site scripting vulnerability has been identified that may allow a remote attacker… | |
| Modificada | Media (6.1) | 1.2% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | |
| Modificada | Media (6.1) | 1.3% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) | |
| Modificada | Crítica (9.8) | 1.8% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version. | |
| Modificada | Alta (8.1) | 0.98% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information. | |
| Modificada | Media (6.5) | 0.83% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function. | |
| Modificada | Media (6.5) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files. | |
| Modificada | Media (6.1) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system. | |
| Modificada | Alta (7.5) | 11% | — | NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+10 | 7/8/2017 | 17/6/2026 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | |
| Modificada | Media (6.5) | 1.8% | — | HP Enterprise Security ManagerHP Enterprise Security Manager Express | 17/3/2016 | 17/6/2026 | HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8) | 1.6% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors. | |
| Modificada | Alta (7.8) | 0.40% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors. | |
| Modificada | Alta (9.3) | 3.4% | — | Mcafee Enterprise Security Manager | 2/12/2015 | 17/6/2026 | McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass… | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Media (6.5) | 1.1% | — | Mcafee Enterprise Security ManagerMcafee Enterprise Security Manager/log ManagerMcafee Enterprise Security Manager/receiver | 22/9/2015 | 17/6/2026 | McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly… | |
| Modificada | Alta (10) | 3.0% | — | Microfocus Arcsight Enterprise Security Manager | 14/3/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors. |