Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

613 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)12%—PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+147/12/201817/6/2026
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
ModificadaAlta (7.8)1.1%💥 ExploitMcafee True KEY6/12/201817/6/2026
Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.
ModificadaAlta (7.8)1.0%💥 ExploitMcafee True KEY6/12/201817/6/2026
Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware.
ModificadaAlta (7.8)0.98%💥 ExploitMcafee True KEY6/12/201817/6/2026
Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.
ModificadaMedia (5.9)0.70%—Mcafee Threat Intelligence Exchange Server3/10/201817/6/2026
SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to spoof servers via acquiring keys from another environment.
ModificadaAlta (7.8)0.36%—Mcafee Data Loss Prevention Endpoint3/10/201817/6/2026
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
ModificadaAlta (7.8)0.94%—Mcafee True KEY24/9/201817/6/2026
DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local users to execute arbitrary code via specially crafted malware.
ModificadaMedia (6.1)0.70%—Mcafee True KEY24/9/201817/6/2026
Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.
ModificadaAlta (7.1)0.26%—Mcafee Application Change Control18/9/201817/6/2026
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
ModificadaAlta (7.8)0.41%—Mcafee Application AND Change Control18/9/201817/6/2026
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
ModificadaMedia (5.3)0.18%—Mcafee Endpoint Security FOR Linux Threat PreventionMcafee Endpoint Security Linux Threat Prevention18/9/201817/6/2026
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete…
ModificadaMedia (6.6)0.24%—Mcafee Drive Encryption27/7/201817/6/2026
Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass local security protection via specific set of circumstances.
ModificadaAlta (7.4)0.30%—Mcafee Data Loss Prevention Endpoint23/7/201817/6/2026
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.
ModificadaCrítica (9.1)1.2%—Mcafee WEB Gateway23/7/201817/6/2026
Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to execute arbitrary commands via unspecified vectors.
ModificadaCrítica (9.1)2.1%—Mcafee WEB Gateway23/7/201817/6/2026
Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors.
ModificadaMedia (5.4)0.50%—Mcafee Network Security Manager17/7/201817/6/2026
Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via appliance web interface.
ModificadaCrítica (9.8)3.5%—Mcafee WEB Gateway26/6/201817/6/2026
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX).
ModificadaMedia (6.5)1.2%—Mcafee Epolicy Orchestrator15/6/201817/6/2026
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.
ModificadaMedia (6.5)2.6%💥 ExploitMcafee Epolicy Orchestrator15/6/201817/6/2026
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
ModificadaCrítica (9.8)1.4%—Mcafee Epolicy Orchestrator13/6/201817/6/2026
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
ModificadaCrítica (9.8)1.6%—Mcafee Threat Intelligence Exchange13/6/201817/6/2026
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.
ModificadaCrítica (9.1)1.5%—Mcafee Network Data Loss PreventionMcafee Network Security Manager13/6/201817/6/2026
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
ModificadaCrítica (9.8)0.35%—Mcafee Network Security Manager12/6/201817/6/2026
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
ModificadaAlta (8.8)0.90%—Mcafee Network Security Manager12/6/201817/6/2026
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privileges via a crafted HTTP request parameter.
ModificadaMedia (6.5)0.97%—Mcafee Common Catalog7/6/201817/6/2026
External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential information via a crafted HTTP request parameter.
Orbitaley — Vulnerabilidades