Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.44% | — | Opentext Arcsight Enterprise Security ManagerAI | 21/4/2025 | 17/6/2026 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Media (4.3) | 0.52% | — | Opentext Arcsight Enterprise Security ManagerAI | 1/3/2024 | 17/6/2026 | A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited. | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Arcsight Enterprise Security Manager | 28/9/2021 | 17/6/2026 | Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution. | |
| Modificada | Media (6.1) | 0.64% | — | Microfocus Arcsight Enterprise Security Manager Express | 16/6/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | |
| Modificada | Media (6.1) | 1.2% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | |
| Modificada | Media (6.1) | 1.3% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) | |
| Modificada | Crítica (9.8) | 1.8% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version. | |
| Modificada | Alta (8.1) | 0.98% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information. | |
| Modificada | Media (6.5) | 0.83% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function. | |
| Modificada | Media (6.5) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files. | |
| Modificada | Media (6.1) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system. | |
| Modificada | Alta (8) | 1.6% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors. | |
| Modificada | Alta (7.8) | 0.40% | — | Microfocus Arcsight Enterprise Security Manager | 16/3/2016 | 17/6/2026 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Alta (10) | 3.0% | — | Microfocus Arcsight Enterprise Security Manager | 14/3/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors. | |
| Modificada | Media (4.3) | 0.94% | — | Microfocus Arcsight Enterprise Security Manager | 20/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |