Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

13 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.1)7.2%—HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+118/22/20166/17/2026
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before…
ModifiedLow (3.7)2.5%—HP Insight Management1/5/20166/17/2026
HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.
ModifiedMedium (4.9)2.0%—HP Insight Management Agents5/2/20126/16/2026
Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.
ModifiedMedium (4.3)3.4%—HP Insight Management Agents5/2/20126/16/2026
Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedHigh (8.3)4.3%—HP Insight Management Agents5/2/20126/16/2026
Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModifiedMedium (6.8)1.9%—HP Insight Management Agents5/2/20126/16/2026
Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModifiedMedium (5)2.3%—HP Insight Management Agents12/22/20106/16/2026
HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.
ModifiedHigh (10)5.2%—HP Insight Management SuiteHP Insight ManagerHP Remote Diagnostics Enabling Agent12/31/20036/16/2026
Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.
ModifiedMedium (4.3)3.0%💥 ExploitCompaq Insight Management Agent12/31/20026/16/2026
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.
ModifiedHigh (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+113/12/20016/16/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
ModifiedHigh (7.5)1.5%—Compaq Insight Management AgentCompaq Management Agents FOR Servers12/31/19996/16/2026
BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.
ModifiedMedium (6.4)1.5%—Compaq Insight Management AgentCompaq Power Management6/1/19996/16/2026
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.
ModifiedMedium (5)6.2%💥 ExploitCompaq Insight Management AgentCompaq Power Management5/26/19996/16/2026
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
Orbitaley — Vulnerabilities