Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.30%—Opentext Enterprise Security ManagerAI25/8/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.
AplazadaMedia (5.7)0.29%—Opentext Enterprise Security ManagerAI25/8/202517/6/2026
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.
AplazadaBaja (2.3)0.44%—Opentext Arcsight Enterprise Security ManagerAI21/4/202517/6/2026
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
AnalizadaCrítica (9.8)2.5%—Trellix Enterprise Security Manager29/11/202417/6/2026
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
AnalizadaAlta (8.2)0.44%—Trellix Enterprise Security Manager29/11/202417/6/2026
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.
AplazadaAlta (8.7)0.35%—Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI20/5/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.
AplazadaAlta (8.7)0.35%—Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI20/5/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.
AplazadaMedia (4.3)0.52%—Opentext Arcsight Enterprise Security ManagerAI1/3/202417/6/2026
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.
ModificadaAlta (7.2)0.85%—Trellix Enterprise Security Manager30/11/202317/6/2026
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.
ModificadaMedia (4.3)0.24%—Trellix Enterprise Security Manager29/11/202317/6/2026
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid…
ModificadaAlta (8.8)0.94%—Trellix Enterprise Security Manager3/7/202317/6/2026
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain…
ModificadaAlta (7.8)0.47%—Trellix Enterprise Security Manager3/7/202317/6/2026
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands.
ModificadaMedia (6.1)0.57%—Microfocus Arcsight Enterprise Security Manager14/1/202217/6/2026
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).
ModificadaMedia (6.1)0.57%—Microfocus Arcsight Enterprise Security Manager14/1/202217/6/2026
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).
ModificadaCrítica (9.8)2.1%—Microfocus Arcsight Enterprise Security Manager28/9/202117/6/2026
Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.
ModificadaMedia (6.1)0.64%—Microfocus Arcsight Enterprise Security Manager Express16/6/202017/6/2026
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
ModificadaAlta (7.5)2.4%—Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway11/9/201917/6/2026
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning proxies.
ModificadaAlta (7.5)2.4%—Mcafee Active ResponseMcafee Advanced Threat DefenseMcafee Enterprise Security ManagerMcafee WEB Gateway11/9/201917/6/2026
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.
ModificadaAlta (8.8)1.7%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.
ModificadaAlta (7.2)2.0%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
ModificadaAlta (7.2)2.0%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
ModificadaMedia (6.5)1.2%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.
ModificadaAlta (8.8)0.98%—Mcafee Enterprise Security Manager27/6/201917/6/2026
Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.
ModificadaMedia (6.1)1.2%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
ModificadaMedia (6.1)1.3%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)