Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.9)0.63%—Symantec PGP Universal Server4/9/201216/6/2026
Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session.
ModificadaBaja (3.3)0.64%—Symantec Messaging Gateway29/8/201216/6/2026
Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors.
ModificadaAlta (7.7)1.1%—Symantec Messaging Gateway29/8/201216/6/2026
Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.
ModificadaAlta (7.9)40%💥 ExploitSymantec Messaging Gateway29/8/201216/6/2026
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.
ModificadaMedia (6.8)1.9%💥 ExploitSymantec Messaging Gateway29/8/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (4.3)2.0%—Symantec Messaging Gateway29/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content.
ModificadaMedia (6.2)0.32%—Symantec Norton Internet Security 201025/8/201216/6/2026
Race condition in Symantec Norton Internet Security 2010 17.5.0.127 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during…
ModificadaMedia (6.4)2.9%—Symantec Norton Antivirus22/8/201216/6/2026
Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop…
ModificadaAlta (7.5)1.2%💥 ExploitSymantec WEB Gateway7/8/201216/6/2026
SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
ModificadaMedia (5)2.8%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
ModificadaAlta (10)5.4%—Symantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.
ModificadaAlta (7.5)2.5%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.2)59%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
ModificadaAlta (10)67%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
ModificadaAlta (7.5)1.2%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.
ModificadaMedia (4.4)0.43%—Symantec Backupexec System RecoverySymantec System Recovery23/7/201216/6/2026
Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
ModificadaMedia (6.8)0.86%—Symantec Message Filter5/7/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.
ModificadaMedia (4.3)1.5%—Symantec Message Filter5/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.77%—Symantec Message Filter5/7/201216/6/2026
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaBaja (3.3)0.81%—Symantec Message Filter5/7/201216/6/2026
Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.
ModificadaMedia (6.9)0.35%—Symantec Liveupdate Administrator22/6/201216/6/2026
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
ModificadaMedia (5)2.8%—Symantec Endpoint Protection24/5/201216/6/2026
The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network…
ModificadaAlta (9.3)4.0%—Symantec Endpoint Protection23/5/201216/6/2026
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
ModificadaMedia (5.8)1.6%—Symantec Endpoint Protection23/5/201216/6/2026
Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors.
ModificadaAlta (7.2)1.5%💥 ExploitSymantec Endpoint ProtectionSymantec Network Access Control23/5/201216/6/2026
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.