Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.1) | 0.24% | — | Arcserve UDP ConsoleAI | 16/4/2026 | 17/6/2026 | UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure. | |
| Modificada | Crítica (9.2) | 0.53% | — | Arcserve UDP | 27/8/2025 | 25/9/2026 | A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when processing attacker-controlled input. By sending specially crafted data, a remote… | |
| Analizada | Crítica (9.2) | 0.56% | — | Arcserve UDP | 27/8/2025 | 25/9/2026 | A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to… | |
| Analizada | Media (4.8) | 0.22% | — | Arcserve UDP | 27/8/2025 | 25/9/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user,… | |
| Analizada | Alta (7.7) | 0.37% | — | Arcserve UDP | 27/8/2025 | 25/9/2026 | An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid… | |
| Analizada | Alta (7.5) | 42% | — | Arcserve UDP | 13/3/2024 | 17/6/2026 | A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. | |
| Analizada | Alta (8.8) | 1.0% | — | Arcserve UDP | 13/3/2024 | 17/6/2026 | A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet. | |
| Analizada | Crítica (9.8) | 4.3% | — | Arcserve UDP | 13/3/2024 | 17/6/2026 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. | |
| Modificada | Crítica (9.8) | 1.5% | — | Arcserve UDP | 27/11/2023 | 17/6/2026 | Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed. | |
| Modificada | Crítica (9.8) | 1.4% | — | Arcserve UDP | 27/11/2023 | 17/6/2026 | An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication. | |
| Modificada | Crítica (9.8) | 15% | — | Arcserve UDP | 27/11/2023 | 17/6/2026 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. | |
| Modificada | Crítica (9.8) | 40% | — | Arcserve UDP | 3/7/2023 | 17/6/2026 | Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as… | |
| Modificada | Alta (7.5) | 74% | — | Arcserve D2D | 20/1/2021 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a… | |
| Modificada | Media (6.1) | 0.90% | — | Arcserve UDP | 26/10/2018 | 17/6/2026 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue. | |
| Modificada | Alta (7.5) | 1.8% | — | Arcserve UDP | 26/10/2018 | 17/6/2026 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue. | |
| Modificada | Alta (7.5) | 1.3% | — | Arcserve UDP | 26/10/2018 | 17/6/2026 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue. | |
| Modificada | Alta (7.5) | 1.3% | — | Arcserve UDP | 26/10/2018 | 17/6/2026 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/services/EdgeServiceImpl issue. | |
| Modificada | Alta (7.8) | 4.5% | — | Arcserve Unified Data Protection | 29/5/2015 | 17/6/2026 | The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method. | |
| Analizada | Crítica (9.1) | 64% | ⚠ Explotación activa | Arcserve UDP | 29/5/2015 | 17/6/2026 | Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet. | |
| Modificada | Media (5) | 3.5% | — | CA Arcserve BackupAI | 20/10/2012 | 16/6/2026 | The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remote attackers to cause a denial of service (service crash) via a crafted request. | |
| Modificada | Alta (7.5) | 4.1% | — | CA Arcserve BackupAI | 20/10/2012 | 16/6/2026 | The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted request. | |
| Modificada | Media (5) | 2.2% | — | Broadcom Arcserve Backup | 22/3/2012 | 16/6/2026 | CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of service (service shutdown) via a crafted network request. | |
| Modificada | Media (5) | 72% | — | CA Arcserve D2D | 15/8/2011 | 16/6/2026 | BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.3% | — | Arcserve Replication AND High AvailabilityCA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication | 7/1/2011 | 16/6/2026 | Buffer overflow in mng_core_com.dll in CA XOsoft Replication r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft High Availability r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft Content Distribution r12.0 SP1 and r12.5 SP2 rollup, and CA ARCserve Replication and High Availability (RHA) r15.0 SP1 allows remote attackers to execute… | |
| Modificada | Baja (2.1) | 0.33% | — | CA Arcserve BackupAI | 7/6/2010 | 16/6/2026 | Unspecified vulnerability in CA ARCserve Backup r11.5 SP4, r12.0 SP2, and r12.5 SP1 on Windows allows local users to obtain sensitive information via unknown vectors. |