Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.24% | — | Veritas System RecoveryAI | 14/5/2024 | 17/6/2026 | Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks. | |
| Aplazada | Media (6.4) | 0.24% | — | Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI | 15/4/2024 | 17/6/2026 | A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code. | |
| Aplazada | Media (6.7) | 0.33% | — | Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI | 15/4/2024 | 17/6/2026 | A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges. | |
| Modificada | Media (6.5) | 0.66% | — | Veritas System Recovery | 23/9/2022 | 17/6/2026 | Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access. | |
| Modificada | Media (6.5) | 0.44% | — | Veritas System Recovery | 10/3/2022 | 17/6/2026 | Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access. | |
| Modificada | Alta (8.8) | 0.45% | — | Veritas System Recovery | 6/1/2021 | 17/6/2026 | An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low… | |
| Modificada | Media (5.5) | 0.62% | — | Symantec Backup Exec System RecoverySymantec Norton 360Symantec Norton GhostSymantec System Recovery 2011 | 19/2/2018 | 16/6/2026 | GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.1% | — | Veritas System Recovery | 5/4/2017 | 17/6/2026 | In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed. | |
| Modificada | Media (4.4) | 0.43% | — | Symantec Backupexec System RecoverySymantec System Recovery | 23/7/2012 | 16/6/2026 | Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (5) | 2.8% | — | Symantec Backupexec System Recovery | 2/6/2008 | 16/6/2026 | Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (10) | 12% | — | Symantec Backupexec System Recovery | 7/2/2008 | 16/6/2026 | Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors. | |
| Modificada | Alta (7.8) | 2.9% | — | Symantec Backupexec System Recovery | 29/11/2007 | 16/6/2026 | Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memory consumption) via a crafted packet to port 5633/tcp, which triggers an infinite loop. | |
| Modificada | Media (5) | 2.6% | — | Symantec Backupexec System Recovery | 29/11/2007 | 16/6/2026 | The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp. | |
| Modificada | Media (4.9) | 0.34% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the… | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string. | |
| Modificada | Media (6.8) | 0.34% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating… |