Vulnerabilities

Summary — last 7 days

New vulnerabilities2,666▼ 407 vs. last week
Critical / high1,266▼ 215 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)215▼ 115 vs. last week
–

123 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (10)65%💥 ExploitHP Openview Network Node Manager11/2/20116/16/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.
ModifiedHigh (10)12%—HP Openview Network Node Manager11/2/20116/16/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209.
ModifiedHigh (10)12%—HP Openview Network Node Manager11/2/20116/16/2026
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208.
ModifiedMedium (4.3)1.5%—HP Openview Performance Insight8/19/20116/16/2026
Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (6.4)2.5%—HP Openview Performance Insight8/11/20116/16/2026
Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors.
ModifiedLow (3.5)0.89%—HP Openview Performance Insight8/11/20116/16/2026
Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (6.4)4.8%—HP Openview Performance AgentHP Operations Agent7/1/20116/16/2026
ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.
ModifiedHigh (10)21%💥 ExploitHP Openview Storage Data Protector7/1/20116/16/2026
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.
ModifiedHigh (10)89%💥 ExploitHP Openview Storage Data Protector7/1/20116/16/2026
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.
ModifiedMedium (5)4.5%—HP Openview Storage Data Protector7/1/20116/16/2026
The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (daemon exit) via a request containing crafted parameters.
ModifiedMedium (5)4.5%—HP Openview Storage Data Protector7/1/20116/16/2026
The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request containing crafted parameters.
ModifiedHigh (9.3)9.2%—HP Openview Storage Data Protector6/14/20116/16/2026
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors.
ModifiedHigh (8.5)9.8%—HP Openview Storage Data Protector5/7/20116/16/2026
Directory traversal vulnerability in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to read arbitrary files via directory traversal sequences in a filename in a GET_FILE message.
ModifiedHigh (10)14%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed bm message.
ModifiedHigh (10)15%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed omniiaputil message.
ModifiedHigh (10)14%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed HPFGConfig message.
ModifiedHigh (10)25%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed stutil message.
ModifiedHigh (10)15%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_INTEGUTIL message.
ModifiedHigh (10)14%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.
ModifiedHigh (10)14%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed GET_FILE message.
ModifiedHigh (10)14%—HP Openview Storage Data Protector5/7/20116/16/2026
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_BAR message.
ModifiedHigh (10)82%💥 ExploitHP Openview Performance Insight2/2/20116/16/2026
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.
ModifiedHigh (7.1)4.2%—HP Openview Storage Data Protector1/28/20116/16/2026
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.
ModifiedHigh (9.3)13%—HP Openview Storage Data Protector Cell Manager1/25/20116/16/2026
Buffer overflow in crs.exe in HP OpenView Storage Data Protector Cell Manager 6.11 allows remote attackers to execute arbitrary code via unspecified message types.
ModifiedHigh (10)7.3%—HP Openview Network Node Manager1/13/20116/16/2026
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."