Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.23% | — | CA Client AutomationAICA ItcmAI | 17/12/2024 | 17/6/2026 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf… | |
| Modificada | Alta (7.8) | 0.62% | — | Broadcom CA Client Automation | 20/12/2019 | 17/6/2026 | An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges. | |
| Modificada | Crítica (9.8) | 5.8% | — | Broadcom CA Client AutomationBroadcom CA Workload Automation AE | 6/9/2019 | 17/6/2026 | An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.30% | — | CA Client Automation | 6/5/2017 | 17/6/2026 | The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation. | |
| Modificada | Alta (7.8) | 0.54% | — | Broadcom CA Workload Automation AEBroadcom Client AutomationBroadcom SystemedgeBroadcom Systems Performance FOR Infrastructure Managers+2 | 27/1/2017 | 17/6/2026 | The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation… | |
| Modificada | Media (5) | 1.7% | — | Accelerite Radia Client Automation | 19/10/2015 | 17/6/2026 | The default configuration of Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 enables a remote Notify capability without the Extended Notify Security features, which might allow remote attackers to bypass intended access restrictions via unspecified… | |
| Modificada | Media (5) | 1.5% | — | Accelerite Radia Client Automation | 19/10/2015 | 17/6/2026 | Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments via unspecified vectors. | |
| Modificada | Alta (10) | 5.4% | — | Accelerite Radia Client Automation | 19/10/2015 | 17/6/2026 | Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling. | |
| Modificada | Alta (10) | 6.1% | — | Accelerite Radia Client Automation | 19/10/2015 | 17/6/2026 | Stack-based buffer overflow in the agent in Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending a large amount of data in an environment that lacks relationship-based firewalling. | |
| Modificada | Media (4.6) | 0.37% | — | CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+2 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Media (4.6) | 0.37% | — | CA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management OptionCA Universal JOB Management Agent+2 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Media (4.6) | 0.46% | — | Broadcom Network AND Systems ManagementCA Client AutomationCA Network AND Systems ManagementCA NSM JOB Management Option+3 | 17/6/2015 | 17/6/2026 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and… | |
| Modificada | Alta (10) | 2.3% | — | Persistent Systems Radia Client Automation | 16/2/2015 | 17/6/2026 | Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3) remove a role from a user account via a… | |
| Modificada | Alta (10) | 74% | — | Persistent Systems Radia Client Automation | 16/2/2015 | 17/6/2026 | radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465. | |
| Modificada | Alta (10) | 13% | — | HP Client Automation Enterprise | 16/3/2011 | 16/6/2026 | Unspecified vulnerability in HP Client Automation Enterprise (aka HPCA or Radia Notify) 5.11, 7.2, 7.5, 7.8, and 7.9 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9) | 2.9% | — | HP Client Automation Enterprise Infrastructure | 22/7/2010 | 16/6/2026 | The default configuration of HP Client Automation (HPCA) Enterprise Infrastructure (aka Radia) allows remote attackers to read log files, and consequently cause a denial of service or have unspecified other impact, via web requests. |