Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Cybozu Remote Service Manager9/1/201917/6/2026
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
ModificadaMedia (6.5)1.0%—Microfocus Service Manager13/11/201817/6/2026
A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data.
ModificadaCrítica (9.8)17%—HP IMC Wireless Service Manager6/8/201817/6/2026
A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version.
ModificadaMedia (5.4)1.2%—Microfocus Service Manager22/5/201817/6/2026
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
ModificadaAlta (8.8)1.8%—IBM Tivoli Business Service Manager9/3/201817/6/2026
IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obtain administrator passwords by leveraging unspecified privileges. BM X-Force ID: 111234.
ModificadaMedia (5.4)0.86%—IBM Tivoli Business Service Manager2/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480.
ModificadaMedia (4.2)0.45%—Cybozu Remote Service Manager28/4/201717/6/2026
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
ModificadaMedia (6.1)0.85%—Cisco Videoscape Distribution Suite Service Manager5/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552.
ModificadaAlta (8)0.83%—HP Service ManagerHP Service Manager MobilityHP Service Manager ServerHP Service Manager Service Request Catalog+219/6/201617/6/2026
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request…
ModificadaAlta (7.5)3.5%—HP Service Manager30/5/201617/6/2026
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components.
ModificadaCrítica (9.8)6.8%—HP Service Manager22/3/201617/6/2026
HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ModificadaMedia (6.5)0.95%—Cisco Videoscape Distribution Suite Service Manager12/12/201517/6/2026
Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025.
ModificadaMedia (5)1.8%—Cisco Videoscape Distribution Suite Service Manager14/11/201517/6/2026
Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960.
ModificadaAlta (7.8)1.8%—Cybozu Remote Service Manager1/2/201517/6/2026
Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983.
ModificadaMedia (5)1.6%—Redhat Virtual Desktop Service Manager22/10/201417/6/2026
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.
ModificadaAlta (9.4)6.4%—HP Service Manager23/8/201417/6/2026
Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.
ModificadaMedia (6.8)1.8%—HP Service Manager23/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (10)13%—HP Service Manager23/8/201417/6/2026
Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.3)3.4%—HP Service Manager23/8/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.76%—IBM Tivoli Business Service Manager12/8/201417/6/2026
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6.8)1.7%—Cybozu Remote Service Manager19/4/201417/6/2026
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaAlta (7.8)2.3%—Cybozu Remote Service Manager19/4/201417/6/2026
Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors.
ModificadaMedia (6.8)2.3%—HP Service Manager24/2/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execute arbitrary code.
ModificadaMedia (4.3)2.6%—HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier29/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.2)0.84%—HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier29/12/201317/6/2026
Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors.