Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · symantec

symantec

· 3 Critical

Total CVEs

571

Critical

3

Products

247

Search All CVEs →

571

Products (247)

endpoint protection71 CVEsnorton antivirus67 CVEsendpoint protection manager41 CVEsnorton internet security40 CVEsweb gateway35 CVEsclient security27 CVEsmessaging gateway25 CVEsaltiris deployment solution24 CVEsnorton system works19 CVEsmail security19 CVEspcanywhere18 CVEsnorton personal firewall18 CVEsantivirus15 CVEsenterprise firewall15 CVEsnorton 36014 CVEsnorton ghost13 CVEsencryption desktop11 CVEsprotection engine10 CVEsantivirus scan engine10 CVEsnorton security10 CVEsmessage gateway10 CVEsendpoint encryption10 CVEsprotection for sharepoint servers9 CVEsencryption management server9 CVEsmail security for domino9 CVEsgateway security9 CVEsbrightmail antispam9 CVEsadvanced threat protection9 CVEscsapi9 CVEsmail security for microsoft exchange9 CVEssygate personal firewall8 CVEsnorton power eraser8 CVEsbackupexec system recovery8 CVEsnorton security with backup8 CVEsendpoint protection cloud7 CVEsdata center security server7 CVEsgateway security 54007 CVEsmessage gateway for service providers7 CVEspgp desktop7 CVEsnorton bootable removal tool7 CVEsghost solutions suite7 CVEsngc7 CVEsvelociraptor7 CVEsweb security7 CVEsweb gateway appliance 84506 CVEsaltiris notification server6 CVEsim manager6 CVEsantivirus central quarantine server6 CVEssystem center6 CVEsraptor firewall6 CVEsdata center security6 CVEsnorton app lock6 CVEsnorton antispam6 CVEsfirewall vpn appliance 1006 CVEsfirewall vpn appliance 2006 CVEsfirewall vpn appliance 200r6 CVEsweb gateway appliance 84906 CVEsliveupdate5 CVEsbackup exec5 CVEsveritas storage foundation5 CVEsworkspace streaming5 CVEsliveupdate administrator5 CVEsbackup exec for windows server4 CVEsendpoint detection and response4 CVEsdiscovery4 CVEsnorton password manager4 CVEssecurity information manager4 CVEsdata loss prevention4 CVEsclientless vpn gateway 44004 CVEsenterprise security manager4 CVEspgp universal server4 CVEsmessage filter4 CVEsclient firewall3 CVEsaltiris client management suite pcanywhere solution3 CVEsaltiris deployment solution remote pcanywhere solution3 CVEsautomated support assistant3 CVEsdata loss prevention detection servers3 CVEsdata loss prevention endpoint agents3 CVEsgateway security 3603 CVEsgateway security 5000 series3 CVEsgateway security 53003 CVEsit management suite3 CVEslivestate recovery3 CVEsmail security 8820 appliance3 CVEsmail security appliance3 CVEsnexland isb soho firewall appliance3 CVEsnexland pro100 firewall appliance3 CVEsnexland pro400 firewall appliance3 CVEsnexland pro800 firewall appliance3 CVEsnexland pro800turbo firewall appliance3 CVEsnexland wavebase firewall appliance3 CVEsnorton family3 CVEsnorton mobile security3 CVEsnorton save and recovery3 CVEsnorton utilities3 CVEsreporter3 CVEsreporting server3 CVEsscan engine3 CVEssecurity information manager appliance3 CVEsveritas backup exec3 CVEsveritas netbackup client3 CVEsveritas netbackup enterprise server3 CVEsveritas netbackup server3 CVEsworkspace virtualization3 CVEssymantec antivirus scan engine caching2 CVEsmessaging gateway for service providers2 CVEsaltiris management platform2 CVEsaltiris it management suite pcanywhere solution2 CVEsemail security.cloud2 CVEsdeployment solution2 CVEsgateway security 360r2 CVEsveritas storage foundation cluster file system for oracle rac2 CVEssecurity analytics2 CVEsendpoint protection for small business2 CVEsnetwork access control2 CVEsbrightmail gateway2 CVEsendpoint protection cloud agent2 CVEssecurityexpressions audit and compliance server2 CVEsmanagement platform2 CVEsgateway security 3202 CVEsdata insight2 CVEsweb security.cloud2 CVEsprotection center2 CVEsnorton core2 CVEsnorton core firmware2 CVEsghost solution suite2 CVEssymantec antivirus filtering \+for domino2 CVEssymantec antivirus filtering domino mpe2 CVEsnetbackup opscenter2 CVEsbrightmail gateway appliance2 CVEsveritas file system2 CVEsproxysg firmware2 CVEssymantec antivirus network attached storage2 CVEssymantec antivirus scan engine2 CVEsmanagement center2 CVEsmanagement console2 CVEson-demand agent1 CVEson-demand protection1 CVEson command ccm1 CVEson command discovery1 CVEson icommand1 CVEsbrightmail appliance1 CVEsbrightmail and messaging gateway1 CVEspowerquest deploycenter1 CVEsbrightmail1 CVEsbackup exec system recovery1 CVEsproxyclient1 CVEsproxysg1 CVEsbackup exec continuous protection server1 CVEssav filter domino nt ports1 CVEssav filter for domino nt1 CVEsweb isolation1 CVEssecurity check1 CVEssecurity check virus detection1 CVEsappstream client1 CVEsaltiris it management suite1 CVEssonar1 CVEssygate management server1 CVEssygate network access control1 CVEsappstream1 CVEssymantec antivirus clearswift1 CVEssymantec antivirus messaging1 CVEssymantec antivirus microsoft sharepoint1 CVEssymantec antivirus ms isa1 CVEssymantec antivirus scan engine clearswift1 CVEssymantec antivirus scan engine for microsoft sharepoint1 CVEssymantec antivirus scan engine for ms isa1 CVEssymantec antivirus scan engine messaging1 CVEssymantec mail security exchange1 CVEssymantec mail security for microsoft exchange1 CVEssymav filter domino nt1 CVEssymdiag1 CVEsantivirus scan engine for network attached storage1 CVEssystem recovery1 CVEssystem recovery 20111 CVEssystem works1 CVEsantivirus engine1 CVEsveritas application director1 CVEsveritas cluster server1 CVEsveritas cluster server management console1 CVEsveritas cluster server one1 CVEsveritas command central enterprise reporter1 CVEsveritas command central storage1 CVEsveritas command central storage change manager1 CVEsveritas dynamic multi-pathing1 CVEsveritas micromeasure1 CVEswindows liveupdate1 CVEswinfax pro1 CVEsveritas netbackup operations manager1 CVEsveritas netbackup reporter1 CVEsaltiris climentent manage suite pcanywhere solution1 CVEsveritas netbackup server \/enterprise server1 CVEsveritas storae foundation1 CVEsanti-virus engine1 CVEsveritas storage foundation cluster file system1 CVEsveritas storage foundation for db21 CVEsidentity portal1 CVEsim manager 20071 CVEsindustrial control system protection1 CVEsinventory1 CVEsit analytics1 CVEsjava1 CVEslivestate agent for windows1 CVEsveritas storage foundation for oracle1 CVEsi-gear1 CVEshost ids1 CVEsmail-gear1 CVEsveritas storage foundation for oracle real application cluster1 CVEsveritas storage foundation for sybase1 CVEsgateway security 53101 CVEsgateway security 51001 CVEsmail threat defense1 CVEsmalware analysis appliance1 CVEsmalware analyzer g21 CVEsmanagement agent1 CVEsveritas storage foundation for high availability1 CVEsgateway security 4601 CVEsgateway security 4001 CVEsmobile security1 CVEsnaveng driver1 CVEsnavex15 driver1 CVEsnetbackup appliance1 CVEsnetbackup enterprise server1 CVEsnetbackup puredisk1 CVEsnetbackup server1 CVEsveritas storage foundation for windows high availability1 CVEsveritas storage foundation manager1 CVEsveritas volume replicator1 CVEsvip1 CVEsvip access desktop1 CVEsvip access for desktop1 CVEsgateway security 3001 CVEsenterprise vault for file system archiving1 CVEsenforce1 CVEsnorton antivirus with backup1 CVEsendpoint protection center1 CVEsnorton download manager1 CVEsvip enterprise gateway1 CVEsnorton internet security 20081 CVEsnorton internet security 20101 CVEsvxfs1 CVEsdata loss prevention enforce\/detection servers1 CVEsdata loss prevention endpoint1 CVEsaltiris wise package studio1 CVEscontent analysis1 CVEsclient intrusion detection system1 CVEsweb gateway appliance1 CVEs

Recent Vulnerabilities

View all 571
CVE-2023-23958MEDIUM 6.8

Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.

CVE-2023-23957MEDIUM 5.4

An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

CVE-2022-25630MEDIUM 5.4

An authenticated user can embed malicious content with XSS into the admin group policy page.

CVE-2022-25629MEDIUM 5.4

An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).

CVE-2022-37015CRITICAL 9.8

Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-25623HIGH 7.8

The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations.

CVE-2021-30642CRITICAL 9.8

An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges.

CVE-2020-12593HIGH 7.5

Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

CVE-2020-5839HIGH 7.5

Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

CVE-2020-5838MEDIUM 4.8

Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.

CVE-2020-5837HIGH 7.8

Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.

CVE-2020-5836HIGH 7.8

Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.

CVE-2020-5835HIGH 7.0

Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.

CVE-2020-5834MEDIUM 5.3

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.

CVE-2020-5833LOW 3.3

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2019-18376MEDIUM 5.9

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

CVE-2020-5832HIGH 7.8

Symantec Data Center Security Manager Component, prior to 6.8.2 (aka 6.8 MP2), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2012-6277HIGH 7.8

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."

CVE-2020-5831LOW 3.3

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5830LOW 3.3

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5829LOW 3.3

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5828LOW 3.3

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5827LOW 3.3

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5826MEDIUM 5.5

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

CVE-2020-5825MEDIUM 5.5

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the resident system without proper privileges.