Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.17% | — | Arctera Enterprise Vault Collection ModuleAIVeritas Ediscovery PlatformAI | 15/4/2025 | 17/6/2026 | Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Media (5.4) | 0.35% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if… | |
| Analizada | Media (5.4) | 1.1% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Analizada | Media (5.4) | 0.35% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Aplazada | Media (5.4) | 0.34% | — | Veritas Enterprise VaultAI | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Alta (8.8) | 0.45% | — | Veritas Enterprise Vault | 6/1/2021 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\) and the product's installation drive… | |
| Modificada | Alta (7.8) | 0.41% | — | Symantec Enterprise Vault FOR File System Archiving | 26/3/2013 | 16/6/2026 | Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program. |