Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.16% | — | HPE Oneview | 18/10/2024 | 17/6/2026 | This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users. | |
| Aplazada | Media (4.3) | 0.16% | — | HPE Icewall AgentAI | 3/10/2024 | 17/6/2026 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow. | |
| Aplazada | Crítica (9.3) | 0.41% | — | HPE Hp-uxAINfsv4AI | 9/9/2024 | 17/6/2026 | HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services. | |
| Aplazada | Alta (7.2) | 0.75% | — | HPE Aruba Networking Edgeconnect Sd-wanAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.68% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.75% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.70% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the… | |
| Aplazada | Alta (7.5) | 0.42% | — | HPE Athonet Mobile CoreAI | 25/6/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying container leading to complete takeover of the target system. | |
| Modificada | Crítica (9.8) | 0.49% | — | HPE Cray Parallel Application Launch Service | 13/6/2024 | 17/6/2026 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | |
| Aplazada | Media (4.3) | 0.41% | — | Paragonie PhpeccAI | 27/4/2024 | 17/6/2026 | phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to phpecc/phpecc on GitHub, and the Matyas Danter ECC library.) | |
| Aplazada | Media (6.8) | 0.43% | — | HPE Compute Scale-up Server 3200AI | 17/4/2024 | 17/6/2026 | A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensitive information in log files. | |
| Aplazada | Media (6.9) | 0.20% | — | HPE FlexfabricAIHPE FlexnetworkAI | 15/4/2024 | 17/6/2026 | A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to gain privileged access to switches resulting in information disclosure. | |
| Aplazada | Alta (7.3) | 0.18% | — | HPE MSAAIHPE VSS ProviderAIHPE Capi ProxyAI | 15/4/2024 | 17/6/2026 | A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system. | |
| Aplazada | Media (6.5) | 0.42% | — | HPE Icewall AgentAI | 26/3/2024 | 17/6/2026 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service. | |
| Modificada | Crítica (9.8) | 0.74% | — | Phpems | 9/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the file app/weixin/controller/index.api.php. The manipulation of the argument picurl leads to deserialization. The exploit has been disclosed to the public and may be used. VDB-253226… | |
| Modificada | Crítica (9.8) | 0.61% | — | HPE Integrated Lights-out 5 FirmwareHPE Integrated Lights-out 6 Firmware | 19/12/2023 | 17/6/2026 | A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass. | |
| Modificada | Alta (8.8) | 1.7% | 💥 PoC | Phpems | 10/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Media (4.8) | 0.60% | — | Phpems | 2/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPEMS 7.0. This issue affects some unknown processing of the file app\content\cls\api.cls.php of the component Content Section Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.2% | — | HPE Oneview | 25/10/2023 | 17/6/2026 | A remote code execution issue exists in HPE OneView. | |
| Modificada | Alta (7.5) | 0.50% | — | HPE Integrated Lights-out 5 FirmwareHPE Integrated Lights-out 6 Firmware | 18/10/2023 | 17/6/2026 | HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service. | |
| Modificada | Media (5.4) | 0.29% | — | HPE MSA 1060 Storage FirmwareHPE MSA 2060 Storage FirmwareHPE MSA 2062 Storage Firmware | 9/10/2023 | 17/6/2026 | HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests. | |
| Modificada | Crítica (9.8) | 0.83% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | |
| Modificada | Media (6.5) | 0.83% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch. | |
| Modificada | Media (6.1) | 0.52% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary… | |
| Modificada | Alta (8.8) | 1.6% | — | HPE Arubaos-cx | 1/8/2023 | 17/6/2026 | An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise… |