Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)21%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Server Protection Suite10/12/200616/6/2026
Desbordamiento de búfer en BrightStor Backup Discovery Service en múltiples productos CA, incluidos ARCserve Backup r11.5 SP1 y anteriores, ARCserve Backup 9.01 hasta la 11.1, Enterprise Backup 10.5 , y CA Server Protection Suite r2, permite a un atacante remoto ejecutar código de su elección a través de vectores no…
ModificadaAlta (10)71%💥 ExploitBroadcom Brightstor Arcserve BackupCA Brightstor Arcserve BackupCA Brightstor Arcserve Backup Agent24/11/200616/6/2026
Desbordamiento de búfer en Tape Engine (tapeeng.exe) en Computer Associates BrightStor ARCserve Backup 11.5 permite a un atacante remoto ejecutar código de su elección a través de ciertas RPC al puerto TCP 6502.
ModificadaAlta (7.5)14%—Broadcom Brightstor Arcserve Backup10/10/200616/6/2026
Desbordamiento de búfer basado en montículo en el cliente y servidor de CA BrightStor ARCserver Backup R11.5 permite a un atacante remoto ejecutar código de su elección a través de mensajes largos al CheyenneDS Mailslot.
ModificadaAlta (7.5)80%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection SuiteBroadcom Server Protection Suite+110/10/200616/6/2026
Múltiples desbordamientos de búfer basado en montón en CA BrightStor ARCserve Backup r11.5 SP1 y anteriores, r11.1, y 9.01; BrightStor ARCServe Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; y Buisiness Protection Suite r2 permiten a un atacante remoto ejecutar código de su…
ModificadaAlta (7.5)3.5%💥 ExploitMambo Bigape-backup Component23/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en classes/Tar.php en el componente bigAPE-Backup(com_babackup) para Mambo 1.1 permite a atacantes remotos incluir archivos de su elección a través del parámetro mosConfig_absolute_path.
ModificadaAlta (9)2.9%—Symantec Veritas Netbackup Puredisk Remote Office Edition18/8/200616/6/2026
Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 anterior a MP1 16/08/2006 permite a atacantes remotos evitar la autenticación y obtener privilegios mediante vectores de ataque desconocidos en la interfaz de administración.
ModificadaMedia (5)12%💥 ExploitSkippy.net Wp-db Backup Plugin FOR Wordpress17/8/200616/6/2026
Vulnerabilidad de escalada de directorio en wp_db_backup.php en la extensión Skippy WP-DB-Backup para WordPress 1.7 y anteriores permietn a usuarios autenticados remotamente con privilegios de administración leer archivos de su elección mediante un .. (punto punto) en el parámetro backup de edit.php.
ModificadaMedia (6.5)5.8%—Symantec Veritas Backup Exec14/8/200616/6/2026
Múliples desbordamientos de búfer en Symantec VERITAS Backup Exec para Netware Server Remote Agent para Windows Server 9.1 y 9.2 (todas las construcciones), Backup Exec Continuous Protection Server Remote Agent para Windows Server 10.1 (10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, y 10.1.327.401), y…
ModificadaAlta (7.1)11%—Veritas Netbackup28/3/200616/6/2026
Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724).
ModificadaAlta (9)8.1%—Veritas Netbackup28/3/200616/6/2026
Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (9)8.1%—Veritas Netbackup28/3/200616/6/2026
Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.6)1.9%—Symantec Veritas Backup Exec19/3/200616/6/2026
Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log…
ModificadaMedia (5)2.2%—Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote Agent19/3/200616/6/2026
Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors."
ModificadaMedia (5)12%💥 ExploitBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+319/1/200616/6/2026
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business…
ModificadaMedia (5)3.8%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+319/1/200616/6/2026
The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection…
ModificadaMedia (4.6)0.57%—Flexbackup31/12/200516/6/2026
Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use.
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaAlta (10)28%💥 ExploitSymantec Veritas Netbackup18/11/200516/6/2026
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet.
ModificadaAlta (10)60%💥 ExploitSymantec Veritas Netbackup Data AND Business CenterSymantec Veritas Netbackup Enterprise Server Client12/10/200516/6/2026
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.
ModificadaBaja (2.1)0.36%—StorebackupSuse Linux5/10/200516/6/2026
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
ModificadaMedia (4.6)0.38%—StorebackupSuse Linux5/10/200516/6/2026
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.
ModificadaBaja (2.1)0.36%—StorebackupSuse Linux5/10/200516/6/2026
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
ModificadaBaja (2.1)0.36%—Debian Backupninja30/9/200516/6/2026
The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack.
ModificadaBaja (2.1)0.33%—Backup Manager Backup-managerAI30/8/200516/6/2026
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
ModificadaBaja (2.1)0.36%—Sukria Backup ManagerDebian Linux30/8/200516/6/2026
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.