Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.16% | — | Checkpoint Harmony Endpoint | 1/5/2024 | 17/6/2026 | A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Analizada | Crítica (9.8) | 0.73% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender… | |
| Analizada | Crítica (9.8) | 0.52% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089… | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet Forticlient Endpoint Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Aplazada | Alta (7.5) | 0.71% | — | Withsecure Client SecurityAIWithsecure Server SecurityAIWithsecure Email AND Server SecurityAIWithsecure Elements Endpoint ProtectionAI+5 | 26/2/2024 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,… | |
| Modificada | Alta (7.8) | 0.55% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 15/2/2024 | 17/6/2026 | Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission. | |
| Modificada | Alta (7.8) | 0.64% | — | Microsoft Defender FOR Endpoint | 13/2/2024 | 10/8/2026 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | |
| Modificada | Media (6.7) | 0.17% | — | Withsecure Client SecurityWithsecure Server SecurityWithsecure Email AND Server SecurityWithsecure Elements Endpoint Protection | 8/2/2024 | 17/6/2026 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later. | |
| Modificada | Alta (7.5) | 33% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 7/2/2024 | 17/6/2026 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker… | |
| Modificada | Alta (7.8) | 0.09% | — | Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server | 6/2/2024 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in… | |
| Modificada | Media (5.5) | 0.28% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+2 | 31/1/2024 | 17/6/2026 | Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions. | |
| Modificada | Alta (7.5) | 0.32% | — | Fireeye Endpoint Security | 15/1/2024 | 17/6/2026 | Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage. | |
| Modificada | Media (6.1) | 0.42% | — | Trellix Endpoint Security WEB Control | 10/1/2024 | 17/6/2026 | A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration. | |
| Modificada | Alta (8.8) | 10.0% | — | Ivanti Endpoint Manager | 9/1/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server. | |
| Modificada | Alta (8.6) | 0.38% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 21/12/2023 | 17/6/2026 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted. | |
| Modificada | Alta (8.2) | 0.46% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+1 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning… | |
| Modificada | Alta (7.5) | 0.70% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Media (5.3) | 0.61% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Media (4.4) | 0.17% | — | Cisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/11/2023 | 17/6/2026 | A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.8) | 0.22% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security | 20/11/2023 | 17/6/2026 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, and WithSecure Elements Endpoint Protection 17 and later. | |
| Modificada | Alta (7.3) | 0.15% | — | Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server | 16/11/2023 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a… | |
| Modificada | Alta (7.5) | 0.70% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 16/11/2023 | 17/6/2026 | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client… | |
| Modificada | Alta (7.5) | 0.70% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 16/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Crítica (9.1) | 1.9% | — | Ivanti Endpoint Manager Mobile | 15/11/2023 | 17/6/2026 | A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk,… |