Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.86% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.1% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (6.9) | 0.62% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Aplazada | Media (6.8) | 0.16% | — | HPE Cray Data Virtualization ServiceAI | 22/4/2025 | 17/6/2026 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access. | |
| Aplazada | Crítica (9.8) | 0.42% | — | HPE Performance Cluster ManagerAI | 22/4/2025 | 17/6/2026 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | |
| Analizada | Alta (8.1) | 0.41% | — | HPE Performance Cluster Manager | 21/4/2025 | 17/6/2026 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. | |
| Aplazada | Media (6.8) | 0.21% | — | HPE Nonstop OSM Service Connection SuiteAI | 10/4/2025 | 17/6/2026 | A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service. | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Aruba Networking Virtual Intranet AccessAIMicrosoft WindowsAI | 1/4/2025 | 17/6/2026 | A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This… | |
| Aplazada | Crítica (9.8) | 0.49% | — | HPE Insight Cluster Management UtilityAI | 30/3/2025 | 17/6/2026 | Unauthenticated RCE in HPE Insight Cluster Management Utility | |
| Analizada | Baja (3.3) | 0.13% | — | HPE Arubaos-cx | 18/3/2025 | 22/9/2026 | A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: | |
| Analizada | Baja (3.4) | 0.23% | — | HPE Arubaos-cx | 8/1/2025 | 22/9/2026 | A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows… | |
| Aplazada | Media (4) | 0.19% | — | HPE Alletra Storage MP B10000AI | 19/12/2024 | 17/6/2026 | Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information. | |
| Analizada | Media (6.5) | 0.70% | — | IBM MQ ApplianceIBM MQ FOR HPE Nonstop | 18/12/2024 | 17/6/2026 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values. | |
| Aplazada | Baja (3.7) | 0.28% | — | HPE IcewallAI | 2/12/2024 | 17/6/2026 | A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification. | |
| Modificada | Crítica (9.8) | 56% | — | HPE Insight Remote Support | 27/11/2024 | 17/6/2026 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | |
| Analizada | Alta (7.5) | 84% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Alta (7.5) | 47% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Crítica (9.8) | 0.72% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code. | |
| Analizada | Alta (7.5) | 1.5% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Aplazada | Media (6.5) | 0.16% | — | HPE Nonstop Disk UtilAI | 22/11/2024 | 17/6/2026 | A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series. | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Cray Data Virtualization ServiceAI | 15/11/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access. | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Data Management Framework SuiteAIHPE CxfsAI | 15/11/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access. |