Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.4%—Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway11/9/201917/6/2026
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning proxies.
ModificadaAlta (7.5)2.4%—Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway11/9/201917/6/2026
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.
ModificadaAlta (8.8)1.7%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.
ModificadaAlta (7.2)2.0%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
ModificadaAlta (7.2)2.0%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
ModificadaMedia (6.5)1.2%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.
ModificadaAlta (8.8)0.98%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.
ModificadaMedia (5.4)0.97%—Tridium NiagaraTridium Niagara AX FrameworkTridium Niagara Enterprise Security29/1/201917/6/2026
Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all versions prior to 4.6.96.28.4 a cross-site scripting vulnerability has been identified that may allow a remote attacker…
ModificadaMedia (6.1)1.2%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
ModificadaMedia (6.1)1.3%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)
ModificadaCrítica (9.8)1.8%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
ModificadaAlta (8.1)0.98%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.
ModificadaMedia (6.5)0.83%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.
ModificadaMedia (6.5)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
ModificadaMedia (6.1)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.
ModificadaAlta (7.5)11%—NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+107/8/201717/6/2026
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
ModificadaMedia (6.5)1.8%—HP Enterprise Security ManagerHP Enterprise Security Manager Express17/3/201617/6/2026
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaAlta (8)1.6%—Microfocus Arcsight Enterprise Security Manager16/3/201617/6/2026
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
ModificadaAlta (7.8)0.40%—Microfocus Arcsight Enterprise Security Manager16/3/201617/6/2026
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.
ModificadaAlta (9.3)3.4%—Mcafee Enterprise Security Manager2/12/201517/6/2026
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass…
ModificadaAlta (7.2)0.61%—HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+34/11/201517/6/2026
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
ModificadaMedia (6.5)1.1%—Mcafee Enterprise Security ManagerMcafee Enterprise Security Manager/log ManagerMcafee Enterprise Security Manager/receiver22/9/201517/6/2026
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly…
ModificadaAlta (10)3.0%—Microfocus Arcsight Enterprise Security Manager14/3/201517/6/2026
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.
Orbitaley — Vulnerabilidades