Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.0%—Symantec Backup Exec5/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) custom-reports generation page, (2) Storage Devices creation page, or (3) jobs creation page in the…
ModificadaAlta (7.9)1.5%—Symantec Backup Exec5/8/201316/6/2026
Heap-based buffer overflow in the utility program in the Linux agent in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via unspecified vectors.
ModificadaMedia (6.8)0.30%—Symantec Encryption DesktopSymantec PGP Desktop5/8/201316/6/2026
Unquoted Windows search path vulnerability in RDDService in Symantec PGP Desktop 10.0.x through 10.2.x and Symantec Encryption Desktop 10.3.0 before MP3 allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory.
ModificadaMedia (5.8)1.3%—Symantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.
ModificadaAlta (7.2)1.1%—Symantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass intended access restrictions via a command.
ModificadaMedia (6)2.7%—Symantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)4.9%—Symantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.4)5.7%—Symantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (8.3)11%💥 ExploitSymantec WEB GatewaySymantec WEB Gateway Appliance 8450Symantec WEB Gateway Appliance 84901/8/201316/6/2026
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script.
ModificadaMedia (4.3)0.89%—Symantec Encryption Management ServerSymantec PGP Universal Server31/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment.
ModificadaBaja (2.9)0.76%—Symantec Security Information ManagerSymantec Security Information Manager Appliance8/7/201316/6/2026
The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls.
ModificadaMedia (4.3)1.5%—Symantec Security Information ManagerSymantec Security Information Manager Appliance8/7/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.7)1.5%—Symantec Security Information ManagerSymantec Security Information Manager Appliance8/7/201316/6/2026
SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.9)4.4%💥 ExploitSymantec Endpoint Protection ManagerSymantec Endpoint Protection Center20/6/201316/6/2026
Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaBaja (3.5)0.84%—Symantec Brightmail Gateway9/5/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in administrative-interface pages in the management console in Symantec Brightmail Gateway 9.5.x allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)0.41%—Symantec Enterprise Vault FOR File System Archiving26/3/201316/6/2026
Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.
ModificadaMedia (6.7)1.2%—Symantec Netbackup Appliance26/3/201316/6/2026
Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.4)0.62%💥 ExploitSymantec PGP DesktopSymantec Encryption Desktop18/2/201316/6/2026
Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application.
ModificadaMedia (6.9)0.26%—Symantec Encryption DesktopSymantec PGP Desktop18/2/201316/6/2026
Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a crafted application.
ModificadaAlta (7.2)0.48%—Symantec Enterprise Security Manager18/12/201216/6/2026
Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise Security Manager (ESM) before 11.0 allow local users to gain privileges via unspecified vectors.
ModificadaAlta (7.2)1.2%—Symantec Endpoint Protection18/12/201216/6/2026
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.2)0.49%—Symantec Network Access Control11/12/201216/6/2026
Unquoted Windows search path vulnerability in Symantec Network Access Control (SNAC) 12.1 before RU2 allows local users to gain privileges via unspecified vectors.
ModificadaMedia (5)59%💥 ExploitSymantec Messaging Gateway5/12/201216/6/2026
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelection parameter in an APPLIANCE…
ModificadaAlta (9.3)6.0%—Symantec AntivirusSymantec Endpoint ProtectionSymantec Scan Engine14/11/201216/6/2026
The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote…
ModificadaMedia (6.8)3.3%—Symantec Ghost Solutions Suite18/10/201216/6/2026
Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted backup file.