Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources. | |
| Modificada | Alta (8.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | |
| Analizada | Media (6.5) | 0.94% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information | |
| Analizada | Alta (8) | 3.1% | — | Ivanti Endpoint Manager | 29/7/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.20% | — | Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+4 | 16/7/2024 | 17/6/2026 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | |
| Aplazada | Media (6.5) | 0.55% | — | Cososys Endpoint ProtectorAIUnify AgentAI | 27/6/2024 | 17/6/2026 | The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain… | |
| Aplazada | Alta (7.2) | 0.78% | — | Netwrix Cososys UnifyAICososys Endpoint ProtectorAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. An attacker with administrative access to the Endpoint Protector or Unify server… | |
| Aplazada | Alta (7.2) | 0.78% | — | Netwrix Cososys UnifyAICososys Endpoint ProtectorAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector and Unify agent which allows an attacker with administrative access to the Endpoint Protector or Unify server to overwrite sensitive… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Netwrix Endpoint ProtectorAICososys UnifyAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector and Unify server application which allows an unauthenticated remote attacker to send a malicious request, resulting in the ability to execute… | |
| Modificada | Alta (8) | 8.5% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8) | 8.5% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8) | 8.2% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8) | 8.5% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8.8) | 72% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8.8) | 100% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8.8) | 100% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8.8) | 100% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8.8) | 64% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older. | |
| Modificada | Media (6.7) | 1.1% | 💥 PoC | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance. | |
| Analizada | Media (6.7) | 1.1% | — | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. | |
| Analizada | Media (6.7) | 0.97% | — | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. | |
| Analizada | Alta (7.8) | 0.40% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security | 22/5/2024 | 17/6/2026 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this… |