Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.96%—Symantec Norton Download Manager14/1/202017/6/2026
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code…
ModificadaMedia (6.1)1.4%💥 PoCSymantec Endpoint Detection AND ResponseFedoraproject Fedora13/1/202017/6/2026
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access…
ModificadaAlta (7.8)0.71%—Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton 360Symantec Norton Antivirus+59/1/202017/6/2026
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path…
ModificadaMedia (5.3)1.4%—Symantec Norton Mobile Security8/1/202017/6/2026
A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.
ModificadaMedia (5.5)0.46%—Symantec Norton Mobile Security8/1/202017/6/2026
An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.
ModificadaMedia (5.4)0.84%—Symantec IT Management Suite8/1/202017/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.
ModificadaBaja (3.7)1.3%—Symantec Norton Mobile Security8/1/202017/6/2026
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.
ModificadaAlta (7.8)0.81%—Symantec VIP Access Desktop8/1/202017/6/2026
A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.
ModificadaAlta (7.1)0.29%—Symantec Norton APP Lock8/1/202017/6/2026
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.
ModificadaAlta (7.8)0.32%—Symantec Encryption DesktopSymantec Endpoint EncryptionSymantec Ghost Solution SuiteSymantec IT Management Suite8/1/202017/6/2026
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x…
ModificadaMedia (6.5)1.7%—Symantec IT Management Suite8/1/202017/6/2026
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.
ModificadaAlta (7.3)1.1%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.
ModificadaMedia (4.8)0.73%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access…
ModificadaAlta (7.2)1.4%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaMedia (6.5)0.56%—Symantec Industrial Control System Protection9/12/201917/6/2026
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
ModificadaCrítica (9.8)1.7%—Broadcom Symantec Critical System Protection25/11/201917/6/2026
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.
ModificadaMedia (5.6)0.30%—Symantec Norton APP Lock18/11/201917/6/2026
Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.
ModificadaAlta (7.8)0.40%—Symantec Endpoint Protection15/11/201917/6/2026
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaAlta (7.8)0.48%—Symantec Endpoint Protection ManagerSymantec Mail Security15/11/201917/6/2026
Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain…
ModificadaMedia (6.7)0.66%—Symantec Endpoint Protection15/11/201917/6/2026
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.
ModificadaAlta (7.8)0.40%—Symantec Endpoint Protection15/11/201917/6/2026
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to 12.1 RU6 MP10d (12.1.7510.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the…
ModificadaBaja (2.3)0.30%—Symantec Endpoint Protection15/11/201917/6/2026
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.
ModificadaAlta (7.8)0.58%💥 PoCSymantec Endpoint Protection Manager15/11/201917/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaMedia (6.1)0.41%—Symantec Sonar1/11/201917/6/2026
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.
ModificadaMedia (4.5)0.48%—Symantec Messaging Gateway24/10/201917/6/2026
Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.