Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.86%—HPE Storeonce System2/6/202517/6/2026
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
AnalizadaCrítica (9.8)1.1%—HPE Storeonce System2/6/202517/6/2026
An authentication bypass vulnerability exists in HPE StoreOnce Software.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaCrítica (9.8)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaMedia (6.9)0.62%—HPE Storeonce System2/6/202517/6/2026
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AplazadaMedia (6.8)0.16%—HPE Cray Data Virtualization ServiceAI22/4/202517/6/2026
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.
AplazadaCrítica (9.8)0.42%—HPE Performance Cluster ManagerAI22/4/202517/6/2026
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.
AnalizadaAlta (8.1)0.41%—HPE Performance Cluster Manager21/4/202517/6/2026
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
AplazadaMedia (6.8)0.21%—HPE Nonstop OSM Service Connection SuiteAI10/4/202517/6/2026
A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service.
AplazadaMedia (5.5)0.14%—HPE Aruba Networking Virtual Intranet AccessAIMicrosoft WindowsAI1/4/202517/6/2026
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This…
AplazadaCrítica (9.8)0.49%—HPE Insight Cluster Management UtilityAI30/3/202517/6/2026
Unauthenticated RCE in HPE Insight Cluster Management Utility
AnalizadaBaja (3.3)0.13%—HPE Arubaos-cx18/3/202522/9/2026
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
AnalizadaBaja (3.4)0.23%—HPE Arubaos-cx8/1/202522/9/2026
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows…
AplazadaMedia (4)0.19%—HPE Alletra Storage MP B10000AI19/12/202417/6/2026
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.
AnalizadaMedia (6.5)0.70%—IBM MQ ApplianceIBM MQ FOR HPE Nonstop18/12/202417/6/2026
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.
AplazadaBaja (3.7)0.28%—HPE IcewallAI2/12/202417/6/2026
A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.
ModificadaCrítica (9.8)56%—HPE Insight Remote Support27/11/202417/6/2026
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
AnalizadaAlta (7.5)84%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaAlta (7.5)47%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaCrítica (9.8)0.72%—HPE Insight Remote Support26/11/202417/6/2026
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
AnalizadaAlta (7.5)1.5%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AplazadaMedia (6.5)0.16%—HPE Nonstop Disk UtilAI22/11/202417/6/2026
A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.
AplazadaMedia (5.5)0.14%—HPE Cray Data Virtualization ServiceAI15/11/202417/6/2026
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
AplazadaMedia (5.5)0.14%—HPE Data Management Framework SuiteAIHPE CxfsAI15/11/202417/6/2026
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
Orbitaley — Vulnerabilidades