Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.28% | — | Dinibh Puzzle Software Solutions Dinibh Patrol Tracking SystemAI | 10/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted Identifiers. This issue affects Dinibh Patrol Tracking System: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond… | |
| Aplazada | Alta (8.7) | 0.46% | — | Positive Technologies MaxpatrolAIPositive Technologies XspiderAI | 14/11/2025 | 17/6/2026 | Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Ancorathemes BugspatrolAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.2) | 0.20% | — | Datapatrol Screenshot WatermarkAI | 17/4/2025 | 17/6/2026 | An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information. NOTE: the Supplier disputes the Print Job Watermark Bypass claim because the watermark is added by hooking into the OS printing mechanism, and thus is not supposed to… | |
| Modificada | Media (4.3) | 1.2% | — | Byzoro Patrolflow-am-2530pro Firmware | 7/12/2023 | 17/6/2026 | A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affects some unknown processing of the file /log/mailsendview.php. The manipulation of the argument file with the input /boot/phpConfig/tb_admin.txt leads to path traversal. The attack may be initiated… | |
| Modificada | Alta (7.8) | 0.27% | — | BMC Patrol Agent | 5/9/2023 | 17/6/2026 | BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host. | |
| Modificada | Alta (7.5) | 0.81% | — | BMC Patrol | 31/5/2023 | 17/6/2026 | An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution. | |
| Modificada | Crítica (9.8) | 1.0% | — | BMC Patrol Agent | 31/5/2023 | 17/6/2026 | An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's… | |
| Modificada | Alta (7.5) | 0.60% | — | Sentrysoftware Hardware Sentry KM FOR BMC Patrol | 23/4/2021 | 17/6/2026 | In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command. | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Alta (7.8) | 0.39% | — | BMC Patrol Agent | 14/10/2019 | 17/6/2026 | An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user by specially crafting a shared library .so file that will be loaded during execution. | |
| Modificada | Alta (7.8) | 0.37% | — | BMC Patrol Agent | 14/10/2019 | 17/6/2026 | An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution. | |
| Modificada | Crítica (9.8) | 6.3% | — | BMC Patrol Agent | 20/5/2019 | 17/6/2026 | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges… | |
| Modificada | Alta (7.8) | 7.5% | — | BMC Patrol Agent | 17/1/2019 | 17/6/2026 | An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided… | |
| Modificada | Alta (7.8) | 0.45% | — | BMC Patrol | 23/8/2017 | 17/6/2026 | mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid root and the RPATH variable begins with the .: substring. | |
| Modificada | Alta (7.8) | 0.47% | — | BMC Patrol | 2/12/2016 | 17/6/2026 | In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their… | |
| Modificada | Media (6.9) | 1.3% | — | BMC Patrol Agent | 14/5/2014 | 17/6/2026 | Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting. | |
| Modificada | Alta (9.3) | 31% | — | CA Etrust Pestpatrole Ppctl.dll Activex | 8/12/2009 | 16/6/2026 | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method. | |
| Modificada | Alta (10) | 7.8% | — | BMC Patrol Agent | 27/1/2009 | 16/6/2026 | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message. | |
| Modificada | Alta (10) | 27% | — | Broadcom Antispyware FOR THE EnterpriseBroadcom Etrust Integrated Threat ManagementBroadcom Etrust Pestpatrol | 11/5/2007 | 16/6/2026 | Stack-based buffer overflow in the inoweb Console Server in CA Anti-Virus for the Enterprise r8, Threat Manager r8, Anti-Spyware for the Enterprise r8, and Protection Suites r3 allows remote attackers to execute arbitrary code via a long (1) username or (2) password. | |
| Modificada | Alta (7.5) | 4.3% | — | BMC Patrol Perform Agent | 22/4/2007 | 16/6/2026 | Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed. | |
| Modificada | Alta (7.5) | 6.7% | — | Broadcom Etrust AntivirusBroadcom Etrust PestpatrolBroadcom Integrated Threat Management | 27/6/2006 | 16/6/2026 | Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP) r8 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the description field. | |
| Modificada | Media (5) | 1.6% | — | Microsys Cyberpatrol | 9/1/2001 | 16/6/2026 | Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information. | |
| Modificada | Alta (7.2) | 0.92% | — | BMC Patrol Agent | 13/7/1999 | 16/6/2026 | BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program. | |
| Modificada | Alta (10) | 2.2% | — | BMC Patrol Agent | 9/4/1999 | 16/6/2026 | BMC Patrol allows remote attackers to gain access to an agent by spoofing frames. |