Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.71% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session. | |
| Modificada | Media (5.4) | 1.5% | 💥 Exploit | Symantec Messaging Gateway | 9/12/2022 | 17/6/2026 | An authenticated user can embed malicious content with XSS into the admin group policy page. | |
| Modificada | Media (5.4) | 0.39% | — | Symantec Messaging Gateway | 9/12/2022 | 17/6/2026 | An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column). | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Broadcom Symantec Endpoint Protection | 1/12/2022 | 17/6/2026 | Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password… | |
| Modificada | Crítica (9.8) | 0.72% | — | Broadcom Symantec Endpoint Protection | 1/12/2022 | 17/6/2026 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | |
| Modificada | Crítica (9.8) | 0.74% | — | Symantec Endpoint Detection AND Response | 8/11/2022 | 17/6/2026 | Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or… | |
| Modificada | Alta (8.8) | 0.84% | — | Broadcom Symantec Privileged Access Management | 26/8/2022 | 17/6/2026 | A malicious unauthorized PAM user can access the administration configuration data and change the values. | |
| Modificada | Media (4.9) | 0.73% | — | Broadcom Symantec Messaging Gateway | 24/6/2022 | 17/6/2026 | A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access. | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Symantec Siteminder | 28/3/2022 | 16/6/2026 | A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.8) | 0.28% | — | Symantec Management Agent | 4/3/2022 | 17/6/2026 | The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations. | |
| Modificada | Crítica (9.8) | 1.4% | — | Broadcom Symantec ProxysgBroadcom Symantec Advanced Secure Gateway S200-30 FirmwareBroadcom Symantec Advanced Secure Gateway S200-40 FirmwareBroadcom Symantec Advanced Secure Gateway S400-20 Firmware+4 | 30/6/2021 | 17/6/2026 | The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance. | |
| Modificada | Crítica (9.8) | 2.7% | — | Symantec Security Analytics | 27/4/2021 | 17/6/2026 | An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges. | |
| Modificada | Media (4.9) | 0.87% | — | Broadcom Symantec Messaging Gateway | 10/12/2020 | 17/6/2026 | An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4. | |
| Modificada | Alta (7.2) | 1.5% | — | Broadcom Symantec Messaging Gateway | 10/12/2020 | 17/6/2026 | A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4. | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Symantec Endpoint Detection AND Response | 18/11/2020 | 17/6/2026 | Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Analizada | Media (5.3) | 4.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+19 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Symantec Endpoint Detection AND Response | 8/7/2020 | 17/6/2026 | Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Modificada | Media (4.8) | 0.69% | — | Symantec IT Analytics | 13/5/2020 | 17/6/2026 | Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users. | |
| Modificada | Alta (7.8) | 0.75% | 💥 PoC | Symantec Endpoint Protection | 11/5/2020 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege. | |
| Modificada | Alta (7.8) | 0.37% | — | Symantec Endpoint Protection | 11/5/2020 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled. | |
| Modificada | Alta (7) | 0.32% | — | Symantec Endpoint Protection Manager | 11/5/2020 | 17/6/2026 | Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine. | |
| Modificada | Media (5.3) | 1.7% | — | Symantec Endpoint Protection Manager | 11/5/2020 | 17/6/2026 | Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory. | |
| Modificada | Baja (3.3) | 0.36% | — | Symantec Endpoint Protection Manager | 11/5/2020 | 17/6/2026 | Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… |