Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.44%—Infoscale CmdserverAI20/5/202623/7/2026
InfoScale CmdServer before 7.4.2 mishandles access control.
AnalizadaAlta (8.8)0.22%—Veritas Infoscale Operations Manager20/5/202623/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.
AnalizadaMedia (5.4)0.24%—Veritas Infoscale Operations Manager20/5/202623/7/2026
InfoScale VIOM 9.1.3 allows XSS.
AnalizadaMedia (6.5)0.35%—Veritas Infoscale Operations Manager20/5/202623/7/2026
SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
AplazadaCrítica (9.8)0.67%—Veritas InfoscaleAI7/3/202517/6/2026
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Plugin_Host service, which runs on all the servers where InfoScale is installed.…
ModificadaAlta (8.8)0.90%—Veritas Infoscale Operations Manager17/7/202317/6/2026
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
ModificadaCrítica (9.8)0.58%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the…
ModificadaAlta (7.2)0.70%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage…
ModificadaMedia (4.9)2.7%—Veritas Infoscale Operations Manager4/3/202217/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By…
ModificadaMedia (4.8)0.45%—Veritas Infoscale Operations Manager4/3/202217/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter…
ModificadaAlta (8.8)0.45%—Veritas InfoscaleVeritas Infoscale Operations ManagerVeritas Storage FoundationVeritas Storage Foundation AND High Availability6/1/202117/6/2026
An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl.…
ModificadaCrítica (9.8)6.1%—Veritas AccessVeritas Access ApplianceVeritas Flex ApplianceVeritas Infoscale+25/11/201917/6/2026
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and…