Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1847 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | El motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) para Mac; Symantec Endpoint… | |
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | Desbordamiento de entero en el desempaquetado TNEF en el motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec… | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | El motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) para Mac; Symantec Endpoint… | |
| Modificada | Alta (7.8) | 53% | — | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | El motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) para Mac; Symantec Endpoint… | |
| Modificada | Alta (7.3) | 11% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | Desbordamiento de buffer en Dec2LHA.dll en el motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint… | |
| Modificada | Alta (7.3) | 21% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | Desbordamiento de buffer en Dec2SS.dll en el motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint Protection… | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | El motor AntiVirus Decomposer en Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x hasta la versión 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) en versiones anteriores a 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) para Mac; Symantec Endpoint… | |
| Modificada | Baja (2.9) | 0.27% | — | Symantec Endpoint Protection Manager | 30/6/2016 | 17/6/2026 | Condición de carrera en el cliente en Symantec Endpoint Protection (SEP) 12.1 en versiones anteriores a RU6 MP5 permite a usuarios locales eludir restricciones destinadas a transferir archivo a USB llevando a cabo operaciones de sistema de archivos antes de que el administrador de dispositivos SEP reconozca un nuevo… | |
| Modificada | Alta (7.3) | 1.2% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x en versiones anteriores a 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 en versiones anteriores a MP1, Critical System Protection (SCSP) en versiones anteriores a 5.2.9 MP6, Data Center Security:… | |
| Modificada | Alta (7.6) | 5.3% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Vulnerabilidad de salto de directorio en el Management Server en Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x en versiones anteriores a 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 en versiones anteriores a MP1, Critical System Protection… | |
| Modificada | Alta (8) | 2.4% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Vulnerabilidad de salto de directorio en el Management Server en Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x en versiones anteriores a 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 en versiones anteriores a MP1, Critical System Protection… | |
| Modificada | Alta (8.8) | 1.5% | — | Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+1 | 8/6/2016 | 17/6/2026 | Vulnerabilidad de inyección SQL en el Management Server en Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x en versiones anteriores a 1.0 MP5, Embedded Security: Critical System Protection for Controllers y Devices (SES:CSP) 6.5.0 en versiones anteriores a MP1, Critical System Protection (SCSP)… | |
| Modificada | Crítica (9.8) | 10% | — | HP Data Protector | 21/4/2016 | 17/6/2026 | HPE Data Protector en versiones anteriores a 7.03_108, 8.x en versiones anteriores a 8.15 y 9.x en versiones anteriores a 9.06 permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados. | |
| Modificada | Crítica (9.8) | 20% | — | HP Data Protector | 21/4/2016 | 17/6/2026 | HPE Data Protector en versiones anteriores a 7.03_108, 8.x en versiones anteriores a 8.15 y 9.x en versiones anteriores a 9.06 permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados, también conocida como ZDI-CAN-3354. | |
| Modificada | Crítica (9.8) | 20% | — | HP Data Protector | 21/4/2016 | 17/6/2026 | HPE Data Protector en versiones anteriores a 7.03_108, 8.x en versiones anteriores a 8.15 y 9.x en versiones anteriores a 9.06 permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados, también conocida como ZDI-CAN-3353. | |
| Modificada | Crítica (9.8) | 20% | — | HP Data Protector | 21/4/2016 | 17/6/2026 | HPE Data Protector en versiones anteriores a 7.03_108, 8.x en versiones anteriores a 8.15 y 9.x en versiones anteriores a 9.06 permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados, también conocida como ZDI-CAN-3352. | |
| Modificada | Crítica (9.8) | 94% | 💥 Exploit | HP Data Protector | 21/4/2016 | 17/6/2026 | HPE Data Protector en versiones anteriores a 7.03_108, 8.x en versiones anteriores a 8.15 y 9.x en versiones anteriores a 9.06 permiten a atacantes remotos ejecutar un código arbitrario a través de vectores no especificados relacionados con la falta de autenticación. NOTA: esta vulnerabilidad existe debido a una… | |
| Modificada | Alta (8.8) | 5.0% | — | Symantec Endpoint Protection Manager | 18/3/2016 | 17/6/2026 | El driver SysPlant.sys en el componente Application and Device Control (ADC) en el cliente en Symantec Endpoint Protection (SEP) 12.1 en versiones anteriores a RU6-MP4 permite a atacantes remotos ejecutar código arbitrario a través de un documento HTML manipulado, relacionada con "RWX Permissions". | |
| Modificada | Alta (8.8) | 3.1% | — | Symantec Endpoint Protection Manager | 18/3/2016 | 17/6/2026 | Vulnerabilidad de inyección SQL en Symantec Endpoint Protection Manager (SEPM) 12.1 en versiones anteriores a RU6-MP4 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados. | |
| Modificada | Alta (8) | 1.7% | — | Symantec Endpoint Protection Manager | 18/3/2016 | 17/6/2026 | Vulnerabilidad de CSRF en Symantec Endpoint Protection Manager (SEPM) 12.1 en versiones anteriores a RU6-MP4 permite a usuarios remotos autenticados secuestrar la autenticación de administradores en peticiones que ejecutan código arbitrario añadiendo líneas a una secuencia de comandos de registro. | |
| Modificada | Crítica (10) | 3.9% | — | IBM Tivoli Storage Flashcopy Manager FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware | 21/2/2016 | 17/6/2026 | El componente Data Protection en la GUI VMware vSphere en IBM Tivoli Storage Manager para Virtual Environments: Data Protection for VMware (también conocido como Spectrum Protect for Virtual Environments) 6.3 en versiones anteriores a 6.3.2.5, 6.4 en versiones anteriores a 6.4.3.1 y 7.1 en versiones anteriores a 7.1.4… | |
| Modificada | Media (5.9) | 2.0% | — | IBM Security Network Protection Firmware | 18/1/2016 | 17/6/2026 | GSKit en IBM Security Network Protection 5.3.1 en versiones anteriores a 5.3.1.7 y 5.3.2 permite a atacantes remotos descubrir credenciales desencadenando una colisión MD5. | |
| Modificada | Crítica (10) | 2.5% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | La extensión Data Protection en la GUI VMware en IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (también conocido como Spectrum Protect for Virtual Environments) 7.1 en versiones anteriores a 7.1.3.0 y Tivoli Storage FlashCopy Manager for VMware (también conocido como Spectrum Protect… | |
| Modificada | Alta (8.5) | 0.98% | — | IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot | 2/1/2016 | 17/6/2026 | La extensión Data Protection en la GUI VMware en IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (también conocido como Spectrum Protect for Virtual Environments) 7.1 en versiones anteriores a 7.1.4 y Tivoli Storage FlashCopy Manager for VMware (también conocido como Spectrum Protect… | |
| Modificada | Baja (1.9) | 0.42% | — | IBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange ServerIBM Tivoli Storage Flashcopy Manager | 14/11/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (también conocido como Spectrum Protect for Databases) 5.5 en versiones anteriores a 5.5.6.2, 6.3 en versiones anteriores a 6.3.1.6, 6.4 en versiones anteriores a 6.4.1.8 y 7.1 en versiones anteriores a 7.1.4; Tivoli Storage Manager for… |