Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)7.3%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.
ModificadaMedia (5)3.1%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2023/8/200516/6/2026
Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability."
ModificadaAlta (10)75%💥 ExploitBroadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (10)87%💥 ExploitSymantec Veritas Backup ExecSymantec Veritas Backup Exec Remote AgentSymantec Veritas Netbackup17/8/200516/6/2026
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the…
ModificadaAlta (7.2)0.41%—Checkpoint Securemote NGAI19/7/200516/6/2026
Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.
ModificadaAlta (7.5)4.9%💥 ExploitDG Remote Control Server19/7/200516/6/2026
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.
ModificadaAlta (7.4)16%💥 PoCMicrosoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP1/6/200516/6/2026
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)66%💥 ExploitNovell ZenworksNovell Zenworks DesktopsNovell Zenworks Remote ManagementNovell Zenworks Server Management+125/5/200516/6/2026
Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2)…
ModificadaMedia (5)3.1%💥 ExploitNiteenterprises Remote File Manager16/5/200516/6/2026
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.
ModificadaMedia (6.8)1.5%—Remote Cart16/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.
ModificadaBaja (2.1)0.35%—Dameware Development Dameware NT UtilitiesDameware Development Miniremote Control2/5/200516/6/2026
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.
ModificadaAlta (7.2)0.35%—Dameware Development Mini Remote ControlDameware Development NT Utilities2/5/200516/6/2026
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
ModificadaBaja (2.1)0.44%—Safenet Softremote VPN Client2/5/200516/6/2026
SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.
ModificadaAlta (10)3.4%—Apple Remote Desktop9/2/200516/6/2026
Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.
ModificadaMedia (5)2.0%—Ibex Software Remote Execute10/1/200516/6/2026
Remote Execute 2.30 allows remote attackers to cause a denial of service (application crash) by making 7 simultaneous connections.
ModificadaAlta (7.5)1.4%—Goosequill Audienceconnect Remoteeditor31/12/200416/6/2026
Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.
ModificadaAlta (10)1.7%—Goosequill Remoteeditor31/12/200416/6/2026
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."
ModificadaAlta (7.5)1.1%—Dameware Development Mini Remote Control Server24/3/200416/6/2026
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
ModificadaMedia (5)0.84%—Solarwinds Dameware Mini Remote Control23/3/200416/6/2026
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
ModificadaAlta (7.5)17%💥 ExploitDameware Development Mini Remote Control Server17/2/200416/6/2026
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.
ModificadaMedia (4.6)0.38%—Broadcom Unicenter Remote Control Host5/1/200416/6/2026
Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to gain privileges via the help interface.
ModificadaMedia (4.6)0.37%—Broadcom Unicenter Remote ControlBroadcom Unicenter Remote Control OptionCA ControlitCA Unicenter Remote Control Option5/1/200416/6/2026
Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2, and ControlIT 5.0 and 5.1, may allow attackers to gain privileges to the local system account.
ModificadaMedia (5)1.3%—Broadcom Unicenter Remote Control Host5/1/200416/6/2026
Unknown "Denial of Service Attack" vulnerability in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to cause a denial of service (CPU consumption in URC host service).
ModificadaAlta (7.5)2.8%—X2 Studios Xmms Remote31/12/200316/6/2026
XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.
Orbitaley — Vulnerabilidades