Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Signiant Manager+agents | 10/3/2022 | 17/6/2026 | Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file on the systems, such as passwd, shadow,… | |
| Modificada | Crítica (9.8) | 1.2% | — | Signiant Manager+agents | 30/1/2022 | 17/6/2026 | Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. | |
| Modificada | Alta (8.8) | 0.82% | — | Jenkins Libvirt Agents | 18/3/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains. | |
| Modificada | Alta (7.8) | 0.50% | — | Webroot Endpoint Agents | 15/6/2020 | 17/6/2026 | Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation. | |
| Modificada | Crítica (9.1) | 1.5% | — | Webroot Endpoint Agents | 15/6/2020 | 17/6/2026 | Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent. | |
| Modificada | Media (5.9) | 0.83% | — | Clusterlabs Fence-agents | 2/1/2020 | 17/6/2026 | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates. | |
| Modificada | Media (5) | 2.2% | — | Clusterlabs Fence-agentsRedhat Enterprise LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 30/7/2019 | 17/6/2026 | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM… | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Azure VM Agents | 8/3/2019 | 17/6/2026 | An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.91% | — | Jenkins Azure VM Agents | 8/3/2019 | 17/6/2026 | A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent. | |
| Modificada | Media (4.3) | 1.0% | — | Jenkins Azure VM Agents | 8/3/2019 | 17/6/2026 | An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to perform the 'verify configuration'… | |
| Modificada | Crítica (9.8) | 1.6% | — | Signiant Manager+agents | 21/2/2019 | 17/6/2026 | In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow. | |
| Modificada | Alta (7.8) | 0.42% | — | Vmware Horizon View Agents | 25/7/2018 | 17/6/2026 | VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this… | |
| Modificada | Alta (7.3) | 1.2% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and… | |
| Modificada | Alta (7.6) | 5.3% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center… | |
| Modificada | Alta (8) | 2.4% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center… | |
| Modificada | Alta (8.8) | 1.5% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security:… | |
| Modificada | Media (5.4) | 0.27% | — | Estateapps Acorn Estate Agents | 19/10/2014 | 17/6/2026 | The Acorn Estate Agents (aka com.acorn.ea) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.6% | — | CA WEB AgentsBroadcom Siteminder | 29/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (double quote) character. | |
| Modificada | Media (4.9) | 2.0% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 3.4% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.3) | 4.3% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.8) | 1.9% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (8.3) | 4.3% | — | HP Snmp Agents FOR Linux | 2/5/2012 | 16/6/2026 | Open redirect vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 3.2% | — | HP Snmp Agents FOR Linux | 2/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.3% | — | HP Insight Management Agents | 22/12/2010 | 16/6/2026 | HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path. |