Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.24%—Veritas System RecoveryAI14/5/202417/6/2026
Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.
AplazadaMedia (6.4)0.24%—Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI15/4/202417/6/2026
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.
AplazadaMedia (6.7)0.33%—Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI15/4/202417/6/2026
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
ModificadaMedia (6.5)0.66%—Veritas System Recovery23/9/202217/6/2026
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
ModificadaMedia (6.5)0.44%—Veritas System Recovery10/3/202217/6/2026
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
ModificadaAlta (8.8)0.45%—Veritas System Recovery6/1/202117/6/2026
An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low…
ModificadaMedia (5.5)0.62%—Symantec Backup Exec System RecoverySymantec Norton 360Symantec Norton GhostSymantec System Recovery 201119/2/201816/6/2026
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.
ModificadaAlta (7.8)1.1%—Veritas System Recovery5/4/201717/6/2026
In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.
ModificadaMedia (4.4)0.43%—Symantec Backupexec System RecoverySymantec System Recovery23/7/201216/6/2026
Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
ModificadaMedia (5)2.8%—Symantec Backupexec System Recovery2/6/200816/6/2026
Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (10)12%—Symantec Backupexec System Recovery7/2/200816/6/2026
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
ModificadaAlta (7.8)2.9%—Symantec Backupexec System Recovery29/11/200716/6/2026
Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memory consumption) via a crafted packet to port 5633/tcp, which triggers an infinite loop.
ModificadaMedia (5)2.6%—Symantec Backupexec System Recovery29/11/200716/6/2026
The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp.
ModificadaMedia (4.9)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the…
ModificadaAlta (7.2)0.41%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.
ModificadaMedia (6.8)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating…