Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
176 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 1.1% | — | IBM Business Process Manager | 10/4/2014 | 17/6/2026 | The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Filenet Case FoundationIBM Filenet Content ManagerIBM Filenet P8 Business Process Manager | 22/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Baja (3.5) | 1.0% | — | IBM Filenet Business Process Framework | 19/12/2013 | 16/6/2026 | IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (10) | 3.4% | — | IBM Business Process Monitor | 13/10/2013 | 16/6/2026 | Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 3.4% | — | IBM Business Process Monitor | 13/10/2013 | 16/6/2026 | Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors, aka ZDI-CAN-1802. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ArchivaApache StrutsFujitsu Interstage Business Process Manager AnalyticsOracle Siebel Apps - E-billing | 20/7/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Business Process Manager | 6/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3)… | |
| Modificada | Media (5) | 1.2% | — | IBM Filenet P8 Content EngineIBM Filenet P8 Business Process ManagerIBM Filenet P8 Content Manager | 21/2/2011 | 16/6/2026 | IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an… | |
| Modificada | Media (5) | 3.4% | — | Broadcom Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Arcserve Backup+1 | 14/10/2008 | 16/6/2026 | Unspecified vulnerability in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash of multiple services) via crafted authentication credentials, related to "insufficient validation." | |
| Modificada | Media (5) | 8.2% | — | Broadcom Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Arcserve Backup+1 | 14/10/2008 | 16/6/2026 | Unspecified vulnerability in the database engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request, related to "insufficient validation." | |
| Modificada | Media (5) | 8.2% | — | Broadcom Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Arcserve Backup+1 | 14/10/2008 | 16/6/2026 | Unspecified vulnerability in the tape engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request. | |
| Modificada | Alta (10) | 81% | 💥 Exploit | Broadcom Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Arcserve Backup+1 | 14/10/2008 | 16/6/2026 | Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A. | |
| Modificada | Alta (10) | 12% | — | Broadcom Brightstor Arcserve BackupBroadcom Server Protection SuiteCA Brightstor Arcserve BackupCA Business Protection Suite | 21/5/2008 | 16/6/2026 | Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many… | |
| Modificada | Alta (7.8) | 55% | 💥 Exploit | Appian Business Process Management Suite | 21/12/2007 | 16/6/2026 | Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp. | |
| Modificada | Alta (10) | 2.2% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection SuiteBroadcom Server Protection Suite+2 | 13/10/2007 | 16/6/2026 | Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption. | |
| Modificada | Alta (10) | 9.9% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection SuiteBroadcom Server Protection Suite+2 | 13/10/2007 | 16/6/2026 | Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers. | |
| Modificada | Alta (10) | 12% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection SuiteBroadcom Server Protection Suite+2 | 13/10/2007 | 16/6/2026 | Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 78% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Brightstor Arcserve Backup+1 | 25/4/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to… | |
| Modificada | Alta (7.8) | 2.8% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+1 | 3/2/2007 | 16/6/2026 | LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\. | |
| Modificada | Alta (7.8) | 3.2% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+1 | 3/2/2007 | 16/6/2026 | LGSERVER.EXE in BrightStor ARCserve Backup for Laptops & Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read. | |
| Modificada | Alta (10) | 79% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Management Suite+1 | 23/1/2007 | 16/6/2026 | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port… | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection Suite | 11/1/2007 | 16/6/2026 | The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection Suite | 11/1/2007 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC… | |
| Modificada | Alta (7.5) | 80% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection SuiteBroadcom Server Protection Suite+1 | 10/10/2006 | 16/6/2026 | Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port… | |
| Modificada | Media (5) | 12% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business… |