Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.98% | — | HPE Autopass License Server | 2/3/2026 | 10/8/2026 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | |
| Aplazada | Alta (7.8) | 0.15% | — | HPE Aruba Networking Clearpass OnguardAI | 18/2/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Analizada | Media (6.5) | 0.32% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.30% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… | |
| Aplazada | Alta (7.5) | 0.72% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory. | |
| Aplazada | Alta (7.2) | 0.88% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Aplazada | Alta (7.8) | 0.17% | — | HPE Aruba Networking Virtual Intranet AccessAI | 13/1/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Aplazada | Alta (7.5) | 0.40% | — | HPE Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets. | |
| Analizada | Media (5.3) | 0.25% | — | Phpems | 1/1/2026 | 17/6/2026 | A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. | |
| Analizada | Baja (2.9) | 0.41% | — | Phpems | 30/12/2025 | 5/10/2026 | A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit… | |
| Modificada | Baja (1.3) | 0.24% | — | Phpems | 30/12/2025 | 5/10/2026 | A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | HPE Oneview | 16/12/2025 | 17/6/2026 | A remote code execution issue exists in HPE OneView. | |
| Analizada | Media (6.5) | 0.29% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data. | |
| Analizada | Alta (7.3) | 0.26% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of… | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system. | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system. | |
| Analizada | Media (6.8) | 0.30% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional. | |
| Analizada | Alta (7.8) | 0.12% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system. | |
| Aplazada | Media (6) | 0.14% | — | HPE Proliant Rl300 Gen11AI | 14/10/2025 | 17/6/2026 | A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware. | |
| Aplazada | Media (6.8) | 0.32% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Aplazada | Alta (7.2) | 0.14% | — | HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI | 16/9/2025 | 17/6/2026 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized… | |
| Aplazada | Alta (7.2) | 0.64% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying… |