Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

588 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A deployselectsoftware expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A devgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)6.9%—HP Intelligent Management Center19/10/202017/6/2026
A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)4.2%—HP Intelligent Management Center19/10/202017/6/2026
A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)11%—HP Intelligent Management Center19/10/202017/6/2026
A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)4.2%—HP Intelligent Management Center19/10/202017/6/2026
A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)7.0%—HP Intelligent Management Center19/10/202017/6/2026
A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaAlta (8.8)1.8%—HP Intelligent Management Center19/10/202017/6/2026
A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaCrítica (9.8)2.9%—HP Intelligent Management Center19/10/202017/6/2026
A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
ModificadaMedia (5.4)0.63%—Cisco Secure Firewall Management CenterCisco Sourcefire Defense Center8/10/202017/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of…
ModificadaCrítica (9.8)3.4%—Cisco Secure Firewall Management Center23/9/202017/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight…
ModificadaAlta (7.2)4.1%—Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense23/9/202011/8/2026
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an…
ModificadaAlta (7.5)1.0%—Microfocus Arcsight Management Center19/8/202017/6/2026
Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service.
ModificadaMedia (6.1)0.85%—Extremenetworks Extreme Management Center5/8/202017/6/2026
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
ModificadaMedia (6.1)0.65%—Extremenetworks Extreme Management Center4/8/202017/6/2026
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
ModificadaMedia (6.1)4.2%💥 ExploitExtremenetworks Extreme Management Center3/8/202017/6/2026
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
Orbitaley — Vulnerabilidades