Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.63%—Urbackup Server7/11/202317/6/2026
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
ModificadaAlta (8.8)1.4%—Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment27/9/202317/6/2026
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.
ModificadaAlta (7.2)1.9%—SAP Adaptive Server Enterprise Backup Server12/5/202017/6/2026
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.
ModificadaMedia (6.1)0.77%—Urbackup Server17/12/201717/6/2026
Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaMedia (6.5)3.4%—Symantec Veritas Netbackup Server /enterprise Server20/2/200916/6/2026
Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Server 5.x, 6.0 before MP7 SP1, and 6.5 before 6.5.3.1 allows remote attackers to execute arbitrary code via unknown vectors related to "initial communications setup."
ModificadaMedia (6.5)2.1%—Symantec Netbackup Enterprise ServerSymantec Netbackup Server30/9/200816/6/2026
Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to "bpjava* binaries."
ModificadaMedia (5)2.2%—EMC Dantz Retrospect Backup Server24/7/200816/6/2026
The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-dependent attackers to recover passwords.
ModificadaAlta (10)30%—Broadcom Brightstor Arcserve Backup Server31/12/200616/6/2026
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is…
ModificadaAlta (10)12%—Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server14/12/200616/6/2026
Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix.
ModificadaAlta (10)12%—Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server14/12/200616/6/2026
Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222.
ModificadaAlta (10)4.3%—Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server14/12/200616/6/2026
The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.
ModificadaMedia (5)1.1%—Symantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server27/7/200516/6/2026
NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.