Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. | |
| Modificada | Media (6.5) | 1.0% | — | Microfocus Service Manager | 13/11/2018 | 17/6/2026 | A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data. | |
| Modificada | Crítica (9.8) | 17% | — | HP IMC Wireless Service Manager | 6/8/2018 | 17/6/2026 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version. | |
| Modificada | Media (5.4) | 1.2% | — | Microfocus Service Manager | 22/5/2018 | 17/6/2026 | Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Tivoli Business Service Manager | 9/3/2018 | 17/6/2026 | IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obtain administrator passwords by leveraging unspecified privileges. BM X-Force ID: 111234. | |
| Modificada | Media (5.4) | 0.86% | — | IBM Tivoli Business Service Manager | 2/2/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480. | |
| Modificada | Media (4.2) | 0.45% | — | Cybozu Remote Service Manager | 28/4/2017 | 17/6/2026 | Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network. | |
| Modificada | Media (6.1) | 0.85% | — | Cisco Videoscape Distribution Suite Service Manager | 5/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. | |
| Modificada | Alta (8) | 0.83% | — | HP Service ManagerHP Service Manager MobilityHP Service Manager ServerHP Service Manager Service Request Catalog+2 | 19/6/2016 | 17/6/2026 | HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request… | |
| Modificada | Alta (7.5) | 3.5% | — | HP Service Manager | 30/5/2016 | 17/6/2026 | HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components. | |
| Modificada | Crítica (9.8) | 6.8% | — | HP Service Manager | 22/3/2016 | 17/6/2026 | HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Videoscape Distribution Suite Service Manager | 12/12/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025. | |
| Modificada | Media (5) | 1.8% | — | Cisco Videoscape Distribution Suite Service Manager | 14/11/2015 | 17/6/2026 | Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960. | |
| Modificada | Alta (7.8) | 1.8% | — | Cybozu Remote Service Manager | 1/2/2015 | 17/6/2026 | Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983. | |
| Modificada | Media (5) | 1.6% | — | Redhat Virtual Desktop Service Manager | 22/10/2014 | 17/6/2026 | VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. | |
| Modificada | Alta (9.4) | 6.4% | — | HP Service Manager | 23/8/2014 | 17/6/2026 | Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors. | |
| Modificada | Media (6.8) | 1.8% | — | HP Service Manager | 23/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (10) | 13% | — | HP Service Manager | 23/8/2014 | 17/6/2026 | Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 3.4% | — | HP Service Manager | 23/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Tivoli Business Service Manager | 12/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.8) | 1.7% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.3% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors. | |
| Modificada | Media (6.8) | 2.3% | — | HP Service Manager | 24/2/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execute arbitrary code. | |
| Modificada | Media (4.3) | 2.6% | — | HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier | 29/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.2) | 0.84% | — | HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier | 29/12/2013 | 17/6/2026 | Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors. |