Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 67% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Desktop Management SuiteCA Protection Suites | 1/10/2007 | 16/6/2026 | Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo… | |
| Modificada | Alta (10) | 73% | 💥 Exploit | Landesk Management Suite | 18/4/2007 | 16/6/2026 | Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Angel Learning Learning Management Suite | 3/3/2007 | 16/6/2026 | SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.8) | 3.2% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+1 | 3/2/2007 | 16/6/2026 | LGSERVER.EXE in BrightStor ARCserve Backup for Laptops & Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read. | |
| Modificada | Alta (7.8) | 2.8% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+1 | 3/2/2007 | 16/6/2026 | LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\. | |
| Modificada | Alta (10) | 79% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Management Suite+1 | 23/1/2007 | 16/6/2026 | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Magnolia Content Management Suite | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (5.8) | 1.7% | 💥 Exploit | HOT Banana WEB Content Management Suite | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | |
| Modificada | Alta (10) | 5.2% | — | HP Insight Management SuiteHP Insight ManagerHP Remote Diagnostics Enabling Agent | 31/12/2003 | 16/6/2026 | Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors. |