Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.36%—HPE Aruba Networking Edgeconnect OSAI16/9/202517/6/2026
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
AplazadaAlta (8.6)0.40%—HPE Aruba Networking Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the internal network, leading to unauthorized access or disruption of services.
AplazadaAlta (8.8)0.47%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying…
AplazadaMedia (6)0.08%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaMedia (6)0.15%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaMedia (6)0.14%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaBaja (3.5)0.20%—HPE Telco Service ActivatorAI31/7/202517/6/2026
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
AplazadaBaja (3.5)0.20%—HPE Telco Service ActivatorAI31/7/202517/6/2026
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
AnalizadaCrítica (9.8)0.52%—HPE Autopass License Server16/7/202517/6/2026
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AnalizadaCrítica (9.8)0.53%—HPE Autopass License Server16/7/202517/6/2026
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AnalizadaCrítica (9.8)0.69%—HPE Autopass License Server16/7/202517/6/2026
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AplazadaAlta (7.1)0.23%—HPE Telco Service OrchestratorAI16/7/202517/6/2026
A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
AnalizadaAlta (7.5)0.42%—HPE Autopass License Server14/7/202517/6/2026
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (7.5)0.42%—HPE Autopass License Server14/7/202517/6/2026
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (8)0.43%—HPE Autopass License Server14/7/202517/6/2026
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (7.3)1.3%—HPE Autopass License Server14/7/202517/6/2026
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AplazadaCrítica (9.8)1.1%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
AplazadaAlta (7.2)1.5%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
AnalizadaCrítica (9.8)0.76%—HPE Insight Remote Support1/7/202517/6/2026
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)46%—HPE Insight Remote Support1/7/202517/6/2026
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)0.54%—HPE Insight Remote Support1/7/202517/6/2026
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
AplazadaAlta (8.7)0.30%—HPE Oneview FOR Vmware VcenterAI26/6/202517/6/2026
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
AplazadaAlta (7.7)0.48%—HPE Aruba Networking Private 5G CoreAI10/6/202517/6/2026
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaMedia (5.9)1.2%—HPE Storeonce System2/6/202517/6/2026
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Orbitaley — Vulnerabilidades