Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.16%—Symantec Data Loss Prevention Windows EndpointAI30/3/202617/6/2026
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to…
AplazadaMedia (5.5)0.51%—Symantec Management PlatformAI16/3/202617/6/2026
A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (4.6)0.24%—Broadcom Symantec Siteminder10/3/202617/6/2026
Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.
AplazadaAlta (8.8)0.24%—Symantec InventoryAI6/3/202617/6/2026
Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitive database…
AplazadaMedia (4.4)0.15%—Symantec Endpoint ProtectionAI28/1/202617/6/2026
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.
AplazadaMedia (6.7)0.17%—Symantec Endpoint ProtectionAI28/1/202617/6/2026
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…
AnalizadaMedia (4.6)0.19%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.
AnalizadaMedia (5.6)0.30%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
AnalizadaAlta (7.5)0.29%—Broadcom Symantec Eraser Engine30/4/202517/6/2026
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
AplazadaAlta (7.8)0.15%—Symantec Diagnostic ToolAI19/2/202517/6/2026
Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
ModificadaMedia (6.8)0.30%—Broadcom Symantec Privileged Access Management15/7/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
ModificadaAlta (8.8)1.7%—Broadcom Symantec Data Center Security Server26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
ModificadaCrítica (9.8)1.9%—Broadcom Symantec Server Management Suite26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
ModificadaCrítica (9.8)1.9%—Broadcom Symantec Messaging Gateway26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
ModificadaCrítica (9.8)1.6%—Broadcom Symantec Messaging Gateway26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
ModificadaCrítica (9.8)1.8%—Broadcom Symantec Deployment Solutions26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
ModificadaMedia (6.5)0.63%—Symantec Protection Engine27/9/202317/6/2026
Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
ModificadaMedia (5.4)0.32%—Symantec Identity Portal19/9/202317/6/2026
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
ModificadaMedia (5.4)3.1%—Broadcom Symantec Siteminder Webagent30/5/202317/6/2026
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
ModificadaMedia (5.4)0.56%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
ModificadaAlta (7.8)0.17%—Broadcom Symantec Endpoint Protection20/1/202317/6/2026
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated
ModificadaAlta (8.8)0.91%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
ModificadaMedia (6.7)0.94%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4