Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.4% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+12 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.4) | 0.24% | — | Mcafee Data Exchange LayerMcafee Threat Intelligence Exchange | 10/4/2019 | 17/6/2026 | Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text via the GUI or command line. | |
| Modificada | Media (4.1) | 0.21% | — | Mcafee Network Security Manager | 26/3/2019 | 17/6/2026 | Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mcafee Network Security Manager | 26/3/2019 | 17/6/2026 | Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect handling of expired GUI sessions. | |
| Modificada | Media (5.5) | 2.0% | — | Systemd Project SystemdOpensuse LeapNetapp Active IQ Performance Analytics ServicesDebian Linux+18 | 21/3/2019 | 17/6/2026 | An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the… | |
| Modificada | Media (6.8) | 0.33% | — | Mcafee Database Security | 12/3/2019 | 17/6/2026 | Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen. | |
| Modificada | Alta (7.5) | 1.8% | — | Mcafee Agent | 28/2/2019 | 17/6/2026 | Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information via remote logging when it is enabled. | |
| Modificada | Media (5.3) | 1.9% | — | Mcafee Agent | 28/2/2019 | 17/6/2026 | Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets. | |
| Modificada | Alta (7.8) | 0.38% | — | Mcafee Endpoint Security | 28/2/2019 | 17/6/2026 | Privilege Escalation vulnerability in Microsoft Windows client in McAfee Endpoint Security (ENS) 10.6.1 and earlier allows local users to gain elevated privileges via a specific set of circumstances. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Crítica (9.8) | 4.7% | — | GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage+2 | 26/2/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. | |
| Modificada | Media (5.5) | 0.82% | — | Mcafee Getsusp | 21/2/2019 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifically crafted file . GetSusp is a free standalone McAfee tool that runs on several versions of Microsoft Windows. | |
| Modificada | Media (5.5) | 0.30% | — | Mcafee True KEY | 13/2/2019 | 17/6/2026 | Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware. | |
| Modificada | Alta (8.8) | 0.44% | — | Mcafee Epolicy Orchestrator | 1/2/2019 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors. | |
| Modificada | Alta (7.1) | 0.35% | — | Mcafee Total Protection | 28/1/2019 | 17/6/2026 | Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without permission via specially crafted malware. | |
| Modificada | Media (6.5) | 1.4% | — | Mcafee Total Protection | 23/1/2019 | 17/6/2026 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder. | |
| Modificada | Media (6) | 0.34% | — | Mcafee Mvision Endpoint | 23/1/2019 | 17/6/2026 | Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove MVision Endpoint via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Mcafee WEB Gateway | 9/1/2019 | 17/6/2026 | Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter. | |
| Modificada | Alta (7.8) | 0.43% | — | Mcafee Application Change Control | 31/12/2018 | 17/6/2026 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DLL through interpreters such as PowerShell. | |
| Modificada | Alta (8) | 0.54% | — | Mcafee Application Change Control | 20/12/2018 | 17/6/2026 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form. | |
| Modificada | Alta (7) | 0.33% | — | Mcafee Agent | 14/12/2018 | 17/6/2026 | Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism. | |
| Modificada | Alta (7.5) | 0.62% | — | Mcafee Agent | 12/12/2018 | 17/6/2026 | Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.38% | — | Mcafee Agent | 12/12/2018 | 17/6/2026 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions. | |
| Modificada | Alta (7.8) | 0.37% | — | Mcafee Agent | 12/12/2018 | 17/6/2026 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions. | |
| Modificada | Crítica (9.8) | 3.2% | — | Mcafee Agent | 11/12/2018 | 17/6/2026 | Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service. |