Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.17%—Opentext Application Lifecycle ManagementAIOpentext Quality CenterAI16/10/202417/6/2026
Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01,…
ModificadaAlta (8.1)0.96%—Microfocus Application Lifecycle Management19/1/202117/6/2026
XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity…
ModificadaBaja (3.3)0.31%—HP Application Lifecycle Management Quality Center Project HP Application Lifecycle Management Quality Center2/7/202017/6/2026
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
ModificadaMedia (6.1)5.2%—Atlassian Subversion Application Lifecycle Management20/3/202017/6/2026
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
ModificadaMedia (4.6)0.55%—HP Application Lifecycle Management12/8/201417/6/2026
Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2138.
ModificadaAlta (7.5)5.5%—HP Application Lifecycle Management4/11/201316/6/2026
Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1327.
AnalizadaCrítica (9.8)79%⚠ Explotación activaHP Application Lifecycle ManagementHP Procurve Manager16/9/201316/6/2026
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of…
ModificadaMedia (4.3)2.1%—HP Application Lifecycle Management29/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ZDI-CAN-1565.