Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.17% | — | Dell Device Management Agent | 1/7/2026 | 6/7/2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service. | |
| Analizada | Media (4.4) | 0.11% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access. | |
| Analizada | Alta (8.3) | 0.13% | — | Eset Management Agent | 6/2/2026 | 3/9/2026 | Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent | |
| Aplazada | Alta (7.1) | 5.8% | — | Acronis VspcAIAcronis Management AgentAI | 4/12/2024 | 17/6/2026 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine. | |
| Aplazada | Alta (7.8) | 0.20% | — | Baramundi Management AgentAI | 15/7/2024 | 17/6/2026 | Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM. | |
| Modificada | Alta (7.8) | 0.28% | — | Symantec Management Agent | 4/3/2022 | 17/6/2026 | The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations. | |
| Modificada | Alta (7.8) | 0.54% | — | Broadcom CA Workload Automation AEBroadcom Client AutomationBroadcom SystemedgeBroadcom Systems Performance FOR Infrastructure Managers+2 | 27/1/2017 | 17/6/2026 | The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation… | |
| Modificada | Media (4.6) | 0.37% | — | CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+2 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Media (4.6) | 0.37% | — | CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+2 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Media (4.6) | 0.46% | — | Broadcom Network AND Systems ManagementCA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management Option+3 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Media (6.4) | 1.4% | — | Tibco Activematrix Management AgentTibco Activematrix Policy AgentTibco Activematrix Policy Manager | 19/2/2015 | 17/6/2026 | The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1.2, ActiveMatrix Management Agent 1.x before 1.2.1 for WCF, and ActiveMatrix Management Agent 1.x before 1.2.1 for WebSphere allows remote attackers to gain privileges… | |
| Modificada | Media (6.5) | 1.1% | — | Mcafee Common Management Agent | 22/8/2012 | 16/6/2026 | McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenticated users to overwrite arbitrary files by accessing a report-writing ActiveX control COM object. | |
| Modificada | Media (4.9) | 2.0% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 3.4% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.3) | 4.3% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.8) | 1.9% | — | HP Insight Management Agents | 2/5/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5) | 2.3% | — | HP Insight Management Agents | 22/12/2010 | 16/6/2026 | HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path. | |
| Modificada | Media (6.9) | 0.32% | — | SUN Snmp Management Agent | 29/12/2008 | 16/6/2026 | Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files. | |
| Modificada | Alta (7.6) | 6.3% | — | Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot | 12/7/2007 | 16/6/2026 | Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Alta (7.6) | 5.0% | — | Mcafee Common Management AgentMcafee Epolicy OrchestratorMcafee Protectionpilot | 12/7/2007 | 16/6/2026 | Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot | 12/7/2007 | 16/6/2026 | Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet. | |
| Modificada | Alta (7.2) | 0.99% | — | Mcafee Common Management AgentMcafee Virusscan Enterprise | 23/12/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path. | |
| Modificada | Media (4.3) | 3.0% | — | Compaq Insight Management Agent | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message. |