Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 3.1% | — | HP Insight Control Server DeploymentHP Rapid Deployment Pack | 14/3/2014 | 17/6/2026 | Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.1) | 0.28% | — | HP Insight Control Server DeploymentHP Rapid Deployment Pack | 14/3/2014 | 17/6/2026 | Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows local users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 1.4% | — | IBM Spss Collaboration AND Deployment Services | 1/2/2014 | 16/6/2026 | The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request. | |
| Modificada | Media (5) | 1.4% | — | IBM Spss Collaboration AND Deployment Services | 21/12/2013 | 16/6/2026 | The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | IBM Spss Collaboration AND Deployment Services | 21/12/2013 | 16/6/2026 | The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5.8) | 1.2% | — | IBM Spss Collaboration AND Deployment Services | 21/12/2013 | 16/6/2026 | Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Spss Collaboration AND Deployment Services | 21/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Spss Collaboration AND Deployment Services | 21/12/2013 | 16/6/2026 | IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request. | |
| Modificada | Alta (10) | 4.2% | — | IBM Spss Collaboration AND Deployment Services | 1/10/2013 | 16/6/2026 | Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-4042. | |
| Modificada | Alta (10) | 4.2% | — | IBM Spss Collaboration AND Deployment Services | 1/10/2013 | 16/6/2026 | Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-5370. | |
| Modificada | Media (4) | 1.9% | — | IBM Websphere Extended Deployment Compute Grid | 28/8/2013 | 16/6/2026 | IBM WebSphere Extended Deployment Compute Grid 8.0 before 8.0.0.3 allows remote authenticated users to obtain sensitive information, and consequently bypass intended access restrictions on jobs, via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.31% | — | Centrify Deployment ManagerCentrify Suite | 4/1/2013 | 16/6/2026 | Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbitrary files and consequently gain privileges via a symlink attack on the centrify.cmd.0 temporary… | |
| Modificada | Media (5) | 2.8% | — | Hitachi Jp1/serverconductor/deploymentmanagerHitachi Serverconductor/deploymentmanager | 25/10/2012 | 16/6/2026 | Directory traversal vulnerability in the PXE Mtftp service in Hitachi JP1/ServerConductor/DeploymentManager before 08-55 Japanese and before 08-51 English allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Symantec PcanywhereSymantec Altiris Client Management Suite Pcanywhere SolutionSymantec Altiris Climentent Manage Suite Pcanywhere SolutionSymantec Altiris Deployment Solution Remote Pcanywhere Solution+1 | 8/3/2012 | 16/6/2026 | The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and… | |
| Modificada | Media (5) | 2.3% | — | Symantec PcanywhereSymantec Altiris Client Management Suite Pcanywhere SolutionSymantec Altiris Deployment Solution Remote Pcanywhere SolutionSymantec Altiris IT Management Suite Pcanywhere Solution | 22/2/2012 | 16/6/2026 | Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote… | |
| Modificada | Alta (10) | 2.3% | — | Symantec PcanywhereSymantec Altiris Client Management Suite Pcanywhere SolutionSymantec Altiris Deployment Solution Remote Pcanywhere Solution | 6/2/2012 | 16/6/2026 | Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly… | |
| Modificada | Baja (3.5) | 0.74% | — | Dell Kace K2000 Systems Deployment Appliance | 12/11/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Dell Kace K2000 Systems Deployment Appliance | 12/11/2011 | 16/6/2026 | The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials. | |
| Modificada | Alta (9.3) | 3.3% | — | Dell Kace K2000 Systems Deployment Appliance | 12/11/2011 | 16/6/2026 | The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access. | |
| Modificada | Media (5) | 1.3% | — | Dell Kace K2000 Systems Deployment Appliance | 12/11/2011 | 16/6/2026 | The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code. | |
| Modificada | Media (5) | 2.5% | — | Dell Kace K2000 Systems Deployment Appliance | 10/4/2011 | 16/6/2026 | The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password. | |
| Modificada | Media (6.8) | 43% | 💥 Exploit | Symantec Altiris Deployment SolutionSymantec Altiris Notification ServerSymantec Management Platform | 7/3/2011 | 16/6/2026 | The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute… | |
| Modificada | Alta (7.5) | 5.9% | — | Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+13 | 7/12/2010 | 16/6/2026 | Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. | |
| Modificada | Alta (7.5) | 3.2% | — | IBM Tivoli Provisioning Manager OS Deployment | 28/10/2010 | 16/6/2026 | The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft… | |
| Modificada | Alta (7.8) | 1.4% | — | Hitachi Serverconductor / Deployment ManagerHitachi Jp1/ Serverconductor / Deployment Manager | 2/7/2010 | 16/6/2026 | Unspecified vulnerability in the Client Service for DPM in Hitachi ServerConductor / Deployment Manager 01-00, 01-01, and 06-00 through 06-00-/A; ServerConductor / Deployment Manager Standard Edition and Enterprise Edition 07-50 through 07-55, and 07-57 through 07-59; and JP1/ServerConductor/Deployment Manager… |