Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Broadcom Symantec Critical System Protection25/11/201917/6/2026
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.
ModificadaAlta (7.3)1.2%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and…
ModificadaAlta (7.6)5.3%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center…
ModificadaAlta (8)2.4%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center…
ModificadaAlta (8.8)1.5%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security:…
ModificadaAlta (7.2)1.5%💥 ExploitBroadcom Symantec Critical System ProtectionSymantec Data Center Security21/1/201517/6/2026
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.
ModificadaMedia (4)9.2%💥 ExploitBroadcom Symantec Critical System ProtectionSymantec Data Center Security21/1/201517/6/2026
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.
ModificadaBaja (3.5)4.6%💥 ExploitBroadcom Symantec Critical System ProtectionSymantec Data Center Security21/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject…
ModificadaMedia (6.5)4.6%💥 ExploitBroadcom Symantec Critical System ProtectionSymantec Data Center Security21/1/201517/6/2026
SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.
ModificadaAlta (9)3.3%—Broadcom Symantec Critical System ProtectionSymantec Data Center Security21/1/201517/6/2026
The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.
ModificadaAlta (7.6)2.4%—Broadcom Symantec Critical System Protection8/5/201416/6/2026
Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to bypass policy settings via unspecified vectors.
Orbitaley — Vulnerabilidades