Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.86% | — | Microfocus Voltage Securemail | 4/2/2022 | 17/6/2026 | A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1. The vulnerability could be exploited to create an information leakage attack. | |
| Modificada | Baja (3.3) | 0.21% | — | Microfocus Operations Agent | 25/1/2022 | 17/6/2026 | Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21. The vulnerability could be exploited by a non-privileged local user to access system monitoring data collected by Operations Agent. | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Media (5.3) | 0.69% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware. | |
| Modificada | Media (5.3) | 0.49% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | |
| Modificada | Media (6.5) | 0.42% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password. | |
| Modificada | Media (6.5) | 0.40% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device. | |
| Modificada | Media (4.6) | 0.09% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages. | |
| Modificada | Media (6.8) | 0.24% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device. | |
| Modificada | Alta (7.8) | 0.17% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services. | |
| Modificada | Alta (8.8) | 60% | 💥 Exploit | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Arcsight Enterprise Security Manager | 28/9/2021 | 17/6/2026 | Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution. | |
| Modificada | Media (4.9) | 0.76% | — | Microfocus Netiq Directory AND Resource Administrator | 28/9/2021 | 17/6/2026 | Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure. | |
| Modificada | Media (5.4) | 0.60% | — | Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server | 14/9/2021 | 17/6/2026 | The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a… | |
| Modificada | Media (5.4) | 0.58% | — | Microfocus Access Manager | 13/9/2021 | 17/6/2026 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | |
| Modificada | Alta (7.5) | 0.73% | — | Microfocus Access Manager | 13/9/2021 | 17/6/2026 | Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | |
| Modificada | Media (6.1) | 0.48% | — | Microfocus Access Manager | 13/9/2021 | 17/6/2026 | Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | |
| Modificada | Media (4.9) | 0.65% | — | Microfocus Access Manager | 13/9/2021 | 17/6/2026 | Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Network Automation | 7/9/2021 | 17/6/2026 | Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication. | |
| Modificada | Media (5.5) | 0.24% | — | Microfocus Access Manager | 2/9/2021 | 17/6/2026 | This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1 | |
| Modificada | Alta (8.8) | 1.0% | — | Microfocus Data Protector | 5/8/2021 | 17/6/2026 | A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and thus allow unintended and unauthorized… | |
| Modificada | Media (6.7) | 0.25% | — | Microfocus Zenworks Configuration ManagementMicrofocus Zenworks Endpoint Security Management | 30/7/2021 | 17/6/2026 | A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges. | |
| Modificada | Alta (7.6) | 0.81% | — | Microfocus Verastream Host Integrator | 22/7/2021 | 17/6/2026 | XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions. | |
| Modificada | Alta (7.1) | 0.62% | — | Microfocus Verastream Host Integrator | 22/7/2021 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data. |