Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.69% | — | Microfocus Netiq Advanced Authentication | 12/7/2021 | 17/6/2026 | Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1. | |
| Modificada | Alta (7.5) | 0.99% | — | Microfocus Secure API Manager | 4/6/2021 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file. | |
| Modificada | Crítica (9.8) | 2.0% | — | Microfocus Sitescope | 28/5/2021 | 17/6/2026 | Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary… | |
| Modificada | Crítica (9.8) | 2.0% | — | Microfocus Application Performance Management | 28/4/2021 | 17/6/2026 | An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM. | |
| Modificada | Media (6.5) | 0.52% | — | SAP Focused RUN | 13/4/2021 | 17/6/2026 | SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert service data collection and sending to SAP without the intended authorization. | |
| Modificada | Crítica (9.8) | 1.5% | — | Microfocus Operations Agent | 13/4/2021 | 17/6/2026 | Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12.14 and 12.15. The vulnerability could be exploited to escalate privileges and execute code under the account of the Operations Agent. | |
| Modificada | Alta (7.2) | 0.76% | — | Microfocus Netiq Advanced Authentication | 12/4/2021 | 17/6/2026 | Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue. | |
| Modificada | Crítica (9.1) | 3.9% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+6 | 12/4/2021 | 17/6/2026 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes… | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Media (6.5) | 1.2% | — | Microfocus Application Automation Tools | 8/4/2021 | 17/6/2026 | Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow access without permission checks. | |
| Modificada | Media (6.5) | 0.72% | — | Microfocus Application Automation Tools | 8/4/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks. | |
| Modificada | Media (6.5) | 0.41% | — | Microfocus Application Automation Tools | 8/4/2021 | 17/6/2026 | Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/TLS certificates. | |
| Modificada | Media (6.1) | 5.0% | — | Microfocus Application Automation Tools | 8/4/2021 | 17/6/2026 | Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects all version 6.7 and earlier versions. | |
| Modificada | Crítica (9.8) | 1.7% | — | Microfocus Operations Bridge Manager | 8/4/2021 | 17/6/2026 | Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access. | |
| Analizada | Alta (7.5) | 26% | ⚠ Explotación activa | Microfocus Access Manager | 26/3/2021 | 17/6/2026 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. | |
| Modificada | Media (6.1) | 0.61% | — | Microfocus Access Manager | 26/3/2021 | 17/6/2026 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Access Manager | 25/3/2021 | 17/6/2026 | Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage. | |
| Modificada | Baja (3.5) | 0.34% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure. | |
| Modificada | Media (4.8) | 0.26% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation. | |
| Modificada | Alta (8) | 0.55% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability. | |
| Modificada | Media (4.8) | 0.32% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS. | |
| Modificada | Alta (8) | 0.61% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations. | |
| Modificada | Media (4.8) | 0.32% | — | Microfocus Solutions Business Manager | 26/2/2021 | 17/6/2026 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding. | |
| Modificada | Crítica (9.8) | 3.5% | — | Microfocus Operations Bridge Manager | 12/2/2021 | 17/6/2026 | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Microfocus Operation Bridge Reporter | 8/2/2021 | 17/6/2026 | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server. |