Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.63% | — | Urbackup Server | 7/11/2023 | 17/6/2026 | UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid. | |
| Modificada | Alta (8.8) | 1.4% | — | Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment | 27/9/2023 | 17/6/2026 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. | |
| Modificada | Alta (7.2) | 1.9% | — | SAP Adaptive Server Enterprise Backup Server | 12/5/2020 | 17/6/2026 | SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection. | |
| Modificada | Media (6.1) | 0.77% | — | Urbackup Server | 17/12/2017 | 17/6/2026 | Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Media (6.5) | 3.4% | — | Symantec Veritas Netbackup Server /enterprise Server | 20/2/2009 | 16/6/2026 | Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Server 5.x, 6.0 before MP7 SP1, and 6.5 before 6.5.3.1 allows remote attackers to execute arbitrary code via unknown vectors related to "initial communications setup." | |
| Modificada | Media (6.5) | 2.1% | — | Symantec Netbackup Enterprise ServerSymantec Netbackup Server | 30/9/2008 | 16/6/2026 | Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to "bpjava* binaries." | |
| Modificada | Media (5) | 2.2% | — | EMC Dantz Retrospect Backup Server | 24/7/2008 | 16/6/2026 | The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-dependent attackers to recover passwords. | |
| Modificada | Alta (10) | 30% | — | Broadcom Brightstor Arcserve Backup Server | 31/12/2006 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is… | |
| Modificada | Alta (10) | 12% | — | Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 14/12/2006 | 16/6/2026 | Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix. | |
| Modificada | Alta (10) | 12% | — | Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 14/12/2006 | 16/6/2026 | Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222. | |
| Modificada | Alta (10) | 4.3% | — | Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 14/12/2006 | 16/6/2026 | The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands. | |
| Modificada | Media (5) | 1.1% | — | Symantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 27/7/2005 | 16/6/2026 | NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference. |