Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.67%—HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Proliant Xl750f Gen9 Server Firmware+973/12/201817/6/2026
The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the…
ModificadaAlta (7.2)4.1%—HP Integrated Lights-out 5 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware27/9/201817/6/2026
A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information.
ModificadaAlta (8.6)3.5%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Integrated Lights-out 5 FirmwareHP Moonshot Chassis Manager Firmware+114/8/201817/6/2026
A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.
ModificadaAlta (8.6)6.2%—HP Integrated Lights-out 3 Firmware6/8/201817/6/2026
A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.
ModificadaMedia (6.1)2.6%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware6/8/201817/6/2026
A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.
ModificadaMedia (6.5)1.4%—HP Moonshot Remote Console AdministratorHP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware15/2/201817/6/2026
A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.
ModificadaBaja (3.7)1.6%—HP Integrated Lights-out 3 Firmware8/9/201617/6/2026
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.
ModificadaCrítica (9.8)3.0%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Integrated Lights-out 4 Mrca Firmware8/9/201617/6/2026
Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware before 2.44, and Integrated Lights-Out 4 (aka iLO 4) mRCA firmware before 2.32 allow remote attackers to obtain sensitive information, modify data, or cause a denial of…
ModificadaMedia (4)2.4%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware30/9/201517/6/2026
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaMedia (6.4)3.5%—HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware31/3/201517/6/2026
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors.
ModificadaAlta (10)10%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware14/6/201316/6/2026
Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (9.3)5.1%—HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware29/11/201216/6/2026
Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors.
Orbitaley — Vulnerabilidades