Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
403 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 72% | 💥 Exploit | Novell Zenworks Asset Management | 8/12/2011 | 16/6/2026 | Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file. | |
| Modificada | Media (4.3) | 1.7% | — | HP AssetcenterHP Assetmanager | 21/10/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP AssetCenter 5.0x through AC_5.03, and AssetManager 5.1x through AM_5.12 and 5.2x through AM_5.22, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Openedit Digital Asset Management | 23/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in data/views/index.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the catalogid parameter. | |
| Modificada | Media (6.8) | 0.58% | — | Openedit Digital Asset Management | 23/2/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to perform unspecified actions as arbitrary users via unknown vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Openedit Digital Asset Management | 23/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Assetman | 22/9/2008 | 16/6/2026 | SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action. | |
| Modificada | Alta (9.3) | 6.8% | — | Computer Associates Arcserve Backup Laptops AND DesktopsComputer Associates Desktop AND Server ManagementComputer Associates Desktop Management SuiteComputer Associates Unicenter Asset Management+3 | 16/4/2008 | 16/6/2026 | The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote… | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Computer Associates Brightstor Arcserve Backup Laptops DesktopsComputer Associates Desktop Management SuiteComputer Associates Unicenter DSM R11 List Control ATXUnicenter Asset Management+3 | 24/3/2008 | 16/6/2026 | Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of… | |
| Modificada | Alta (9.3) | 24% | — | Broadcom Advantage Data TransportBroadcom Brightstor PortalBroadcom Brightstor SAN ManagerBroadcom Cleverpath Aion+20 | 26/7/2007 | 16/6/2026 | Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain… | |
| Modificada | Alta (7.2) | 0.39% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 23/7/2007 | 16/6/2026 | Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges. | |
| Modificada | Alta (9.3) | 4.7% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of… | |
| Modificada | Alta (10) | 7.8% | — | Centennial DiscoveryNumara Asset ManagerSymantec Discovery | 16/5/2007 | 16/6/2026 | Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Assetman | 13/3/2007 | 16/6/2026 | Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Arcserve BrightstorBroadcom Cleverpath PortalCleverpath Aion BPMCleverpath Portal+7 | 20/12/2006 | 16/6/2026 | Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are… | |
| Modificada | Alta (10) | 9.7% | — | Novell Zenworks Asset Management | 5/12/2006 | 16/6/2026 | Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute arbitrary code via crafted packets, which trigger a heap-based buffer overflow. | |
| Modificada | Media (5.8) | 1.3% | — | John Frank Asset Manager | 30/5/2006 | 16/6/2026 | ** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in John Frank Asset Manager (AssetMan) 2.4a and earlier allows remote attackers to inject arbitrary web script or HTML via "any of its input." NOTE: the original disclosure is based on… | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Yusasp WEB Asset Manager | 18/5/2005 | 16/6/2026 | YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp. | |
| Modificada | Alta (7.5) | 1.4% | — | Broadcom Unicenter Asset Management | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in the Query Designer for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to execute arbitrary SQL via an imported file. | |
| Modificada | Media (4.6) | 0.36% | — | Broadcom Unicenter Asset Management | 2/3/2005 | 16/6/2026 | Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods. | |
| Modificada | Media (4.3) | 1.3% | — | Broadcom Unicenter Asset Management | 2/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template. | |
| Modificada | Alta (7.2) | 0.65% | — | Passive Asset Detection System PadsAI | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability. |