Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Symantec Data Loss Prevention Windows EndpointAI | 30/3/2026 | 17/6/2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to… | |
| Aplazada | Media (5.5) | 0.51% | — | Symantec Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (4.6) | 0.24% | — | Broadcom Symantec Siteminder | 10/3/2026 | 17/6/2026 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | |
| Aplazada | Alta (8.8) | 0.24% | — | Symantec InventoryAI | 6/3/2026 | 17/6/2026 | Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitive database… | |
| Aplazada | Media (4.4) | 0.15% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry. | |
| Aplazada | Media (6.7) | 0.17% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | |
| Analizada | Media (4.6) | 0.19% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user. | |
| Analizada | Media (5.6) | 0.30% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | |
| Analizada | Alta (7.5) | 0.29% | — | Broadcom Symantec Eraser Engine | 30/4/2025 | 17/6/2026 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user. | |
| Aplazada | Alta (7.8) | 0.15% | — | Symantec Diagnostic ToolAI | 19/2/2025 | 17/6/2026 | Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability. | |
| Modificada | Media (6.8) | 0.30% | — | Broadcom Symantec Privileged Access Management | 15/7/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI. | |
| Modificada | Alta (8.8) | 1.7% | — | Broadcom Symantec Data Center Security Server | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Broadcom Symantec Server Management Suite | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. | |
| Modificada | Crítica (9.8) | 1.9% | — | Broadcom Symantec Messaging Gateway | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. | |
| Modificada | Crítica (9.8) | 1.6% | — | Broadcom Symantec Messaging Gateway | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. | |
| Modificada | Crítica (9.8) | 1.8% | — | Broadcom Symantec Deployment Solutions | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. | |
| Modificada | Media (6.5) | 0.63% | — | Symantec Protection Engine | 27/9/2023 | 17/6/2026 | Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability. | |
| Modificada | Media (5.4) | 0.32% | — | Symantec Identity Portal | 19/9/2023 | 17/6/2026 | An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4 | |
| Modificada | Media (5.4) | 3.1% | — | Broadcom Symantec Siteminder Webagent | 30/5/2023 | 17/6/2026 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. | |
| Modificada | Media (5.4) | 0.56% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. | |
| Modificada | Alta (7.8) | 0.17% | — | Broadcom Symantec Endpoint Protection | 20/1/2023 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated | |
| Modificada | Alta (8.8) | 0.91% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | |
| Modificada | Media (6.7) | 0.94% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4 |