Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.17%—Dell Device Management Agent1/7/20266/7/2026
Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaAlta (7.8)0.14%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaMedia (5.5)0.12%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.
AnalizadaMedia (4.4)0.11%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access.
AnalizadaAlta (8.3)0.13%—Eset Management Agent6/2/20263/9/2026
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
AplazadaAlta (7.1)5.8%—Acronis VspcAIAcronis Management AgentAI4/12/202417/6/2026
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.
AplazadaAlta (7.8)0.20%—Baramundi Management AgentAI15/7/202417/6/2026
Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM.
ModificadaAlta (7.8)0.28%—Symantec Management Agent4/3/202217/6/2026
The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations.
ModificadaAlta (7.8)0.54%—Broadcom CA Workload Automation AEBroadcom Client AutomationBroadcom SystemedgeBroadcom Systems Performance FOR Infrastructure Managers+227/1/201717/6/2026
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation…
ModificadaMedia (4.6)0.37%—CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+217/6/201517/6/2026
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and…
ModificadaMedia (4.6)0.37%—CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+217/6/201517/6/2026
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and…
ModificadaMedia (4.6)0.46%—Broadcom Network AND Systems ManagementCA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management Option+317/6/201517/6/2026
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and…
ModificadaMedia (6.4)1.4%—Tibco Activematrix Management AgentTibco Activematrix Policy AgentTibco Activematrix Policy Manager19/2/201517/6/2026
The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1.2, ActiveMatrix Management Agent 1.x before 1.2.1 for WCF, and ActiveMatrix Management Agent 1.x before 1.2.1 for WebSphere allows remote attackers to gain privileges…
ModificadaMedia (6.5)1.1%—Mcafee Common Management Agent22/8/201216/6/2026
McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenticated users to overwrite arbitrary files by accessing a report-writing ActiveX control COM object.
ModificadaMedia (4.9)2.0%—HP Insight Management Agents2/5/201216/6/2026
Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.
ModificadaMedia (4.3)3.4%—HP Insight Management Agents2/5/201216/6/2026
Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.3)4.3%—HP Insight Management Agents2/5/201216/6/2026
Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.8)1.9%—HP Insight Management Agents2/5/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (5)2.3%—HP Insight Management Agents22/12/201016/6/2026
HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.
ModificadaMedia (6.9)0.32%—SUN Snmp Management Agent29/12/200816/6/2026
Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.
ModificadaAlta (7.6)6.3%—Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot12/7/200716/6/2026
Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet.
ModificadaAlta (7.6)5.0%—Mcafee Common Management AgentMcafee Epolicy OrchestratorMcafee Protectionpilot12/7/200716/6/2026
Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)3.6%—Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot12/7/200716/6/2026
Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet.
ModificadaAlta (7.2)0.99%—Mcafee Common Management AgentMcafee Virusscan Enterprise23/12/200516/6/2026
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.
ModificadaMedia (4.3)3.0%—Compaq Insight Management Agent31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.