Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.30% | — | Opentext Enterprise Security ManagerAI | 25/8/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | |
| Aplazada | Media (5.7) | 0.29% | — | Opentext Enterprise Security ManagerAI | 25/8/2025 | 17/6/2026 | An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | |
| Aplazada | Baja (2.3) | 0.44% | — | Opentext Arcsight Enterprise Security ManagerAI | 21/4/2025 | 17/6/2026 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. | |
| Analizada | Crítica (9.8) | 2.5% | — | Trellix Enterprise Security Manager | 29/11/2024 | 17/6/2026 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user. | |
| Analizada | Alta (8.2) | 0.44% | — | Trellix Enterprise Security Manager | 29/11/2024 | 17/6/2026 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints. | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Media (4.3) | 0.52% | — | Opentext Arcsight Enterprise Security ManagerAI | 1/3/2024 | 17/6/2026 | A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited. | |
| Modificada | Alta (7.2) | 0.85% | — | Trellix Enterprise Security Manager | 30/11/2023 | 17/6/2026 | An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source. | |
| Modificada | Media (4.3) | 0.24% | — | Trellix Enterprise Security Manager | 29/11/2023 | 17/6/2026 | A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid… | |
| Modificada | Alta (8.8) | 0.94% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain… | |
| Modificada | Alta (7.8) | 0.47% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands. | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.57% | — | Microfocus Arcsight Enterprise Security Manager | 14/1/2022 | 17/6/2026 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Arcsight Enterprise Security Manager | 28/9/2021 | 17/6/2026 | Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution. | |
| Modificada | Media (6.1) | 0.64% | — | Microfocus Arcsight Enterprise Security Manager Express | 16/6/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | |
| Modificada | Alta (7.5) | 2.4% | — | Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway | 11/9/2019 | 17/6/2026 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning proxies. | |
| Modificada | Alta (7.5) | 2.4% | — | Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway | 11/9/2019 | 17/6/2026 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies. | |
| Modificada | Alta (8.8) | 1.7% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Media (6.5) | 1.2% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters. | |
| Modificada | Alta (8.8) | 0.98% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control. | |
| Modificada | Media (6.1) | 1.2% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | |
| Modificada | Media (6.1) | 1.3% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) |