Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.71%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
ModificadaMedia (5.4)1.5%💥 ExploitSymantec Messaging Gateway9/12/202217/6/2026
An authenticated user can embed malicious content with XSS into the admin group policy page.
ModificadaMedia (5.4)0.39%—Symantec Messaging Gateway9/12/202217/6/2026
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
ModificadaAlta (7.5)1.2%💥 PoCBroadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password…
ModificadaCrítica (9.8)0.72%—Broadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaCrítica (9.8)0.74%—Symantec Endpoint Detection AND Response8/11/202217/6/2026
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or…
ModificadaAlta (8.8)0.84%—Broadcom Symantec Privileged Access Management26/8/202217/6/2026
A malicious unauthorized PAM user can access the administration configuration data and change the values.
ModificadaMedia (4.9)0.73%—Broadcom Symantec Messaging Gateway24/6/202217/6/2026
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
ModificadaMedia (6.1)0.72%—Broadcom Symantec Siteminder28/3/202216/6/2026
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.8)0.28%—Symantec Management Agent4/3/202217/6/2026
The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations.
ModificadaCrítica (9.8)1.4%—Broadcom Symantec ProxysgBroadcom Symantec Advanced Secure Gateway S200-30 FirmwareBroadcom Symantec Advanced Secure Gateway S200-40 FirmwareBroadcom Symantec Advanced Secure Gateway S400-20 Firmware+430/6/202117/6/2026
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.
ModificadaCrítica (9.8)2.7%—Symantec Security Analytics27/4/202117/6/2026
An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges.
ModificadaMedia (4.9)0.87%—Broadcom Symantec Messaging Gateway10/12/202017/6/2026
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.
ModificadaAlta (7.2)1.5%—Broadcom Symantec Messaging Gateway10/12/202017/6/2026
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4.
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaAlta (7.5)2.0%💥 PoCSymantec Endpoint Detection AND Response18/11/202017/6/2026
Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.
AnalizadaMedia (5.3)4.3%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1915/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.5)2.0%💥 PoCSymantec Endpoint Detection AND Response8/7/202017/6/2026
Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.
ModificadaMedia (4.8)0.69%—Symantec IT Analytics13/5/202017/6/2026
Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.
ModificadaAlta (7.8)0.75%💥 PoCSymantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
ModificadaAlta (7.8)0.37%—Symantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.
ModificadaAlta (7)0.32%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.
ModificadaMedia (5.3)1.7%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.
ModificadaBaja (3.3)0.36%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaMedia (5.3)4.9%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
Orbitaley — Vulnerabilidades