Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1909 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.47%—Tibco HawkTibco Hawk Monitoring AgentTibco Runtime Agent5/6/200616/6/2026
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
ModificadaMedia (5)5.1%—Winagents Tftp Server24/4/200616/6/2026
Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.
ModificadaMedia (5)2.2%—Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote Agent19/3/200616/6/2026
Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors."
ModificadaMedia (6.4)55%💥 ExploitRSA Authentication Agent FOR WEB31/12/200516/6/2026
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.
ModificadaAlta (7.2)0.37%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop31/12/200516/6/2026
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary…
ModificadaMedia (4.6)0.44%—Sygate Technologies Protection Agent28/12/200516/6/2026
SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local users to obtain management control over the agent by executing the GUI (SmcGui.exe) and then killing the process, which causes the privileged management GUI to launch.
ModificadaAlta (7.2)0.99%💥 ExploitMcafee Common Management AgentMcafee Virusscan Enterprise23/12/200516/6/2026
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.
ModificadaAlta (7.8)2.6%—Apani Networks Epiforce Agent17/12/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Apani Networks EpiForce 1.9 and earlier running IPSec, allow remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is…
ModificadaAlta (7.8)3.7%—Trend Micro Serverprotect Earthagent14/12/200516/6/2026
Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic…
ModificadaAlta (7.2)0.40%—Cisco Security AgentAI29/11/200516/6/2026
Unspecified vulnerability in Cisco Security Agent (CSA) 4.5.0 and 4.5.1 agents, when running on Windows systems, allows local users to bypass protections and gain system privileges by executing certain local software.
ModificadaMedia (4.3)2.2%💥 ExploitRSA Authentication Agent FOR WEB27/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.
ModificadaBaja (2.1)0.38%—BMC Software Control-m Agent26/10/200516/6/2026
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (10)87%💥 ExploitSymantec Veritas Backup ExecSymantec Veritas Backup Exec Remote AgentSymantec Veritas Netbackup17/8/200516/6/2026
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the…
ModificadaBaja (2.1)0.48%—Network Associates Epolicy Orchestrator Agent12/8/200516/6/2026
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.
ModificadaAlta (7.5)66%💥 ExploitBroadcom Brightstor Enterprise BackupCA Brightstor Arcserve BackupCA Brightstor Arcserve Backup AgentCA Brightstor Enterprise Backup Agent5/8/200516/6/2026
Desbordamiento de búfer en Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 permite que atacantes remotos ejecuten código arbitrario mediante el envío de una cadena larga al puerto 6070 ó 6050.
ModificadaMedia (5)1.3%—Cisco Security Agent18/7/200516/6/2026
Cisco Security Agent (CSA) 4.5 permite que atacantes remotos causen una denegación de servicio (caída del sistema) mediante un paquete IP manipulado.
ModificadaMedia (5)1.8%—Vipul Razor-agents17/6/200516/6/2026
Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)2.6%—RSA Securid WEB Agent6/5/200516/6/2026
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.
ModificadaMedia (4.3)2.5%💥 ExploitRSA Authentication Agent FOR WEB14/4/200516/6/2026
Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.
ModificadaMedia (4.6)0.31%—Sygate Technologies Security Agent12/4/200516/6/2026
Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.
ModificadaMedia (5.1)1.5%—Cisco Security AgentOkena Stormwatch10/1/200516/6/2026
The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
ModificadaMedia (4.6)0.42%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop31/12/200416/6/2026
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.
ModificadaMedia (5)2.5%—Winagents Tftp ServerAI31/12/200416/6/2026
WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.
ModificadaMedia (5)59%💥 ExploitNortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+1523/12/200416/6/2026
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number…