Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.5% | — | HP Service ManagerHP Service Center | 29/11/2013 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, 9.31, and 9.32, and ServiceCenter 6.2.8, allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | — | HP Service Manager | 16/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | HP Service Manager | 16/10/2013 | 16/6/2026 | HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.5) | 1.1% | — | HP Service Manager | 16/10/2013 | 16/6/2026 | HP Service Manager 9.30 through 9.32 does not properly manage privileges, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.6% | — | HP Service Manager | 16/10/2013 | 16/6/2026 | HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach. | |
| Modificada | Alta (10) | 4.4% | — | HP Service CenterHP Service Manager | 18/8/2013 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31 and Service Center 6.2.8 allows remote attackers to obtain privileged access via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | — | HP Service ManagerHP Service Center | 14/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | HP Service ManagerHP Service Center | 14/6/2013 | 16/6/2026 | HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | HP Service Manager WEB Tier | 2/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | HP Service Manager WEB Tier | 2/5/2013 | 16/6/2026 | HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | HP Service Center WEB TierHP Service Manager WEB Tier | 16/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 7.11, 9.21, and 9.30, and HP Service Center Web Tier 6.28, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.4% | — | HP Service Center ServerHP Service Manager Server | 16/8/2012 | 16/6/2026 | Unspecified vulnerability in HP Service Manager Server 7.11, 9.21, and 9.30, and HP Service Center Server 6.28, allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors. | |
| Modificada | Media (4.3) | 1.8% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.3) | 2.3% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors. | |
| Modificada | Media (5) | 2.3% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors. | |
| Modificada | Media (5) | 2.3% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 0.29% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (8.2) | 1.6% | — | HP Service CenterHP Service Manager | 14/6/2011 | 16/6/2026 | Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (9) | 3.6% | — | HP Service Manager | 17/11/2008 | 16/6/2026 | Unspecified vulnerability in HP Service Manager (HPSM) before 7.01.71 allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Cisco Building Broadband Service Manager | 16/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Baja (2.1) | 0.44% | — | IBM Tivoli Business Service Manager | 25/1/2008 | 16/6/2026 | IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information. | |
| Modificada | Media (6.8) | 5.6% | — | Motive Incorporated Self Service ManagerMotive Incorporated Service Activation Manager | 15/8/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.9) | 0.33% | — | IBM Tivoli Business Service Manager | 11/4/2007 | 16/6/2026 | IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log. | |
| Modificada | Alta (7.5) | 6.3% | — | Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+15 | 21/12/2004 | 16/6/2026 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. |