Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 8.8% | — | Microsoft System Center Operations Manager | 15/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "System Center Operations Manager Web Console XSS Vulnerability." | |
| Modificada | Media (6.8) | 0.33% | — | HP Operations Manager I Management Pack | 14/3/2015 | 17/6/2026 | HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges. | |
| Modificada | Alta (7.5) | 6.4% | — | HP Operations ManagerLinux Kernel | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Operations Manager 9.20 on UNIX allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 8.9% | — | HP Operations Manager | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 76% | 💥 Exploit | Vmturbo Operations Manager | 29/8/2014 | 17/6/2026 | vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call. | |
| Modificada | Media (4.3) | 1.8% | — | Fujitsu Serverview Operations Manager | 14/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Fujitsu ServerView Operations Manager 5.00.09 through 6.30.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.5) | 3.4% | — | HP Operations Manager I | 26/5/2014 | 17/6/2026 | Unspecified vulnerability in HP Operations Manager i 9.1 through 9.13 and 9.2 through 9.24 allows remote authenticated users to execute arbitrary code by leveraging the OMi operator role. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Vmturbo Operations Manager | 21/5/2014 | 17/6/2026 | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the xml_path parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Cisco Video Surveillance Operations Manager | 24/1/2014 | 17/6/2026 | Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID… | |
| Modificada | Media (5) | 1.3% | — | Cisco Video Surveillance Operations Manager | 30/9/2013 | 16/6/2026 | The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262. | |
| Modificada | Media (5) | 1.6% | — | Cisco Prime LAN Management SolutionCisco Security ManagerCisco Unified Operations ManagerCisco Unified Service Monitor | 12/9/2013 | 16/6/2026 | Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to cause a denial of service (memory consumption) via… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Unified Operations Manager | 23/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cisco Unified Operations Manager allow remote attackers to inject arbitrary web script or HTML, and obtain improperly secured cookies, via unspecified vectors, aka Bug ID CSCud80186. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Unified Operations Manager | 23/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a crafted URL in an unspecified HTTP header field, aka Bug ID CSCud80182. | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Unified Operations Manager | 23/7/2013 | 16/6/2026 | SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179. | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Unified Operations ManagerCisco Unified Service Monitor | 10/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web framework in the unified-communications management implementation in Cisco Unified Operations Manager and Unified Service Monitor allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuh47574 and CSCuh95997. | |
| Modificada | Media (4.3) | 0.96% | — | Cisco Video Surveillance Operations Manager | 14/6/2013 | 16/6/2026 | Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. | |
| Modificada | Media (4.3) | 17% | — | Microsoft System Center Operations Manager | 9/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009. | |
| Modificada | Media (4.3) | 14% | — | Microsoft System Center Operations Manager | 9/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010. | |
| Modificada | Alta (10) | 11% | — | Cisco Unified Service MonitorCiscoworks LAN Management SolutionCisco Unified Operations ManagerEMC Ionix ACM+2 | 19/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for… | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716. | |
| Modificada | Media (4.3) | 21% | 💥 Exploit | Cisco Unified Operations Manager | 20/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to… | |
| Modificada | Alta (10) | 6.0% | — | Ciscoworks Common ServicesCiscoworks LAN Management SolutionCisco QOS Policy ManagerCisco Security Manager+3 | 29/10/2010 | 16/6/2026 | Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | HP Operations Manager | 21/4/2010 | 16/6/2026 | Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll. | |
| Modificada | Alta (10) | 11% | — | Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+19 | 11/12/2009 | 16/6/2026 | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)… |