Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · ca

ca

· Vendor

Total CVEs

138

Critical

0

Products

108

Search All CVEs →

138

Products (108)

brightstor arcserve backup19 CVEsetrust secure content manager15 CVEsprotection suites13 CVEsbusiness protection suite11 CVEsarcserve backup11 CVEsetrust antivirus8 CVEsetrust intrusion detection7 CVEsunicenter management6 CVEsunified infrastructure management5 CVEsanti-virus for the enterprise5 CVEsunicenter software delivery5 CVEsuniversal job management agent4 CVEsservice desk manager4 CVEsgateway security4 CVEsproject portfolio management4 CVEsxosoft content distribution4 CVEsinternet security suite plus 20084 CVEsinternet security suite 20084 CVEsworkload automation ae4 CVEsvirtual assurance for infrastructure managers4 CVEsclient automation4 CVEscloud service management4 CVEsunicenter tng4 CVEsxosoft replication4 CVEsehealth performance manager4 CVEsunicenter enterprise job manager4 CVEsxosoft high availability4 CVEsunicenter asset management4 CVEsapi developer portal3 CVEsnsm job management option3 CVEsetrust vet antivirus3 CVEsetrust admin3 CVEsthreat manager3 CVEsnetwork and systems management3 CVEsehealth3 CVEshost-based intrusion prevention system3 CVEsunicenter web services distributed management2 CVEsanti-virus2 CVEsanti-virus gateway2 CVEsanti-virus plus2 CVEsarcot webfort versatile authentication server2 CVEsarcserve backup 20002 CVEsarcserve for windows client agent2 CVEsarcserve for windows server component2 CVEsbrightstor arcserve backup agent2 CVEscommon services2 CVEsetrust anti-virus gateway2 CVEsetrust anti-virus sdk2 CVEsetrust ez antivirus2 CVEsidentityminder2 CVEsinternet security suite 20102 CVEsinternet security suite plus 20092 CVEsmessaging2 CVEsrisk authentication2 CVEssiteminder2 CVEsstrong authentication2 CVEsthreat manager for the enterprise2 CVEsthreat manager total defense2 CVEsunicenter remote control2 CVEsidentity manager1 CVEspersonal firewall 20071 CVEspersonal firewall 20081 CVEsidentity governance1 CVEshost based intrusion prevention system1 CVEspsformx active x control1 CVEsbrightstor arcserve client1 CVEsservice desk1 CVEsservice desk management1 CVEsetrust pestpatrole ppctl.dll activex1 CVEsservice level management1 CVEsservice metric analysis1 CVEsworkload control center1 CVEssoftware delivery1 CVEsspectrum1 CVEsxcom data transport1 CVEsetrust directory1 CVEsarcserve replication and high availability1 CVEsarcserve d2d1 CVEsunicenter application performance monitor1 CVEsunicenter application server managment1 CVEsetrust audit aries1 CVEsunicenter ca web services distributed management1 CVEsetrust access control1 CVEsunicenter exchange management console1 CVEserwin web portal1 CVEsunicenter nsm1 CVEsarcserve backup for laptops and desktops1 CVEsunicenter remote control option1 CVEsunicenter service catalog fulfillment accounting1 CVEsunicenter service fulfillment1 CVEsunicenter service level management1 CVEscontrolit1 CVEscmdb1 CVEsunicenter web server management1 CVEsadvantage data transport1 CVEsca privileged access manager1 CVEsunified infrastructure management snap1 CVEsbrightstor enterprise backup agent1 CVEsvet antivirus1 CVEsinternet security suite 20071 CVEsbrightstor enterprise backup1 CVEsinternet security suite 20111 CVEsinternet security suite1 CVEsweb agents1 CVEsinternet security suite plus 20101 CVEsit client manager1 CVEswebscan active x control1 CVEsidentity manager virtual appliance1 CVEs

Recent Vulnerabilities

View all 138
CVE-2021-28250HIGH 7.8

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-28249HIGH 8.8

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the library will be executed as the root user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-28247MEDIUM 5.4

CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The affected endpoints are: cgi/nhWeb with the parameter report, aviewbin/filtermibobjects.pl with the parameter namefilter, and aviewbin/query.pl with the parameters System, SystemText, Group, and GroupText. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2019-7394HIGH 8.8

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges.

CVE-2019-7393MEDIUM 4.3

A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.

CVE-2018-19635

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

CVE-2018-19634HIGH 7.5

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

CVE-2018-13826

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.

CVE-2018-13825

Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.

CVE-2018-13824

Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.

CVE-2018-13823

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.

CVE-2018-13821

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.

CVE-2018-13820

A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

CVE-2018-13819

A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

CVE-2018-9027

A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.

CVE-2018-6589HIGH 7.5

CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVE-2018-8954

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

CVE-2018-8953

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

CVE-2018-6588MEDIUM 6.1

CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.

CVE-2018-6587MEDIUM 6.1

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

CVE-2018-6586MEDIUM 6.1

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.

CVE-2017-9394

A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.

CVE-2017-9393

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.

CVE-2017-8391

The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.

CVE-2016-9165

The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.