Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.44% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data. | |
| Pendiente de análisis | Alta (8.1) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values. | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data. | |
| Pendiente de análisis | Crítica (9.9) | 0.37% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | |
| Pendiente de análisis | Alta (7.5) | 0.27% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation. | |
| Aplazada | Media (6.8) | 0.21% | — | HPE Nonstop OSM Service Connection SuiteAI | 10/4/2025 | 17/6/2026 | A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service. | |
| Analizada | Media (6.5) | 0.70% | — | IBM MQ ApplianceIBM MQ FOR HPE Nonstop | 18/12/2024 | 17/6/2026 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values. | |
| Aplazada | Media (6.5) | 0.16% | — | HPE Nonstop Disk UtilAI | 22/11/2024 | 17/6/2026 | A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series. | |
| Modificada | Alta (7.5) | 0.66% | — | IBM MQ FOR HPE Nonstop | 27/2/2023 | 17/6/2026 | IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Force ID: 235727. | |
| Modificada | Alta (7.8) | 0.18% | — | HP Nonstop Netbatch-plus | 22/11/2022 | 17/6/2026 | A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details. | |
| Modificada | Alta (7.5) | 1.3% | — | HPE Nonstop Distributed Systems Management / Software Configuration Manager | 28/6/2022 | 17/6/2026 | A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM. | |
| Modificada | Media (5.5) | 0.23% | — | IBM MQ FOR HPE Nonstop | 13/5/2022 | 17/6/2026 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM MQ FOR HPE Nonstop | 14/12/2021 | 17/6/2026 | IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404. | |
| Modificada | Media (6.5) | 1.4% | — | IBM MQ FOR HPE Nonstop | 20/7/2020 | 17/6/2026 | IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due to an error within the Queue processing function. IBM X-Force ID: 181563. | |
| Modificada | Media (6.5) | 1.1% | — | IBM MQ FOR HPE Nonstop | 1/7/2020 | 17/6/2026 | IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service caused by an error within the pubsub logic. IBM X-Force ID: 179081. | |
| Modificada | Alta (7) | 0.31% | — | IBM MQ FOR HPE Nonstop | 29/5/2020 | 17/6/2026 | IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427. | |
| Modificada | Alta (7) | 0.32% | — | HP Nonstop Safeguard H SeriesHP Nonstop Safeguard J SeriesHP Nonstop Safeguard L SeriesHP Nonstop Standard Security H Series+2 | 10/5/2019 | 17/6/2026 | A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions… | |
| Modificada | Media (4.4) | 0.58% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found. | |
| Modificada | Alta (7.5) | 7.5% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found. | |
| Modificada | Media (5.5) | 0.60% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found. | |
| Modificada | Alta (9) | 2.0% | — | HP Nonstop Safeguard Security | 25/5/2015 | 17/6/2026 | Unspecified vulnerability in HP NonStop Safeguard Security Software H06.x, L15.02, and J06.x before J06.19 allows remote authenticated users to gain privileges by leveraging Expand access. | |
| Modificada | Media (4) | 2.1% | — | HP Nonstop Safeguard Security | 12/8/2014 | 17/6/2026 | HP NonStop Safeguard Security Software G, H06.03 through H06.28.01, and J06.03 through J06.17.01 does not properly evaluate the DISKFILE-PATTERN ACL of a program object file, which allows remote authenticated users to bypass intended restrictions on program access via vectors related to process-creation time. | |
| Modificada | Media (5.2) | 1.1% | — | HP Nonstop Netbatch | 1/8/2014 | 17/6/2026 | Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors. | |
| Modificada | Media (6) | 1.2% | — | HP Nonstop Sql/mx | 28/6/2013 | 16/6/2026 | HP SQL/MX 3.0 through 3.2 on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to bypass intended access restrictions and modify data via unspecified vectors, aka the "SQL/MP tables" issue. | |
| Modificada | Baja (3.5) | 1.0% | — | HP Nonstop Sql/mx | 28/6/2013 | 16/6/2026 | HP SQL/MX 3.2 and earlier on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to obtain sensitive information via unspecified vectors, aka the "SQL/MP index" issue. |