Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.17%—Broadcom Symantec Endpoint Protection20/1/202317/6/2026
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated
ModificadaAlta (7.1)0.19%—Cisco RoomosCisco Telepresence Collaboration EndpointCisco Telepresence TC20/1/202317/6/2026
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are in the local file system. An attacker could exploit this…
ModificadaMedia (4.4)0.16%—Cisco RoomosCisco Telepresence Collaboration Endpoint20/1/202317/6/2026
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+1818/1/202331/7/2026
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,…
ModificadaMedia (6)0.23%—Trellix Endpoint Security16/12/202217/6/2026
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.
ModificadaAlta (7.8)0.76%—Ivanti Endpoint Manager5/12/202217/6/2026
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.
ModificadaCrítica (9.8)2.8%—Ivanti Endpoint Manager5/12/202217/6/2026
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
ModificadaAlta (7.5)1.2%💥 PoCBroadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password…
ModificadaCrítica (9.8)0.72%—Broadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaAlta (7.5)0.70%—F-secure Elements Endpoint Protection25/11/202217/6/2026
In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.
ModificadaAlta (7.8)0.17%—Intel Endpoint Management Assistant11/11/202217/6/2026
Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.47%—Intel Active Management Technology Software Development KITIntel Endpoint Management AssistantIntel Manageability Commander11/11/202217/6/2026
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.
ModificadaCrítica (9.8)0.74%—Symantec Endpoint Detection AND Response8/11/202217/6/2026
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or…
ModificadaAlta (7.1)0.44%—Cisco Telepresence Collaboration EndpointCisco Roomos26/10/202217/6/2026
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this…
ModificadaAlta (7.1)0.44%—Cisco Telepresence Collaboration EndpointCisco Roomos26/10/202217/6/2026
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this…
ModificadaMedia (5.5)0.43%—Cisco Telepresence Collaboration EndpointCisco Roomos26/10/202217/6/2026
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this…
ModificadaAlta (7.2)0.72%—Cisco Telepresence Collaboration EndpointCisco Roomos26/10/202217/6/2026
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this…
ModificadaMedia (6.7)0.49%—Cisco Telepresence Collaboration EndpointCisco Roomos26/10/202217/6/2026
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this…
ModificadaAlta (7.5)0.40%—F-secure Elements Endpoint Detection AND ResponseF-secure Elements Endpoint ProtectionF-secure AtlantF-secure Internet Gatekeeper+212/10/202217/6/2026
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
ModificadaMedia (5.5)0.47%—F-secure Cloud Protection FOR SalesforceF-secure Collaboration ProtectionF-secure Elements Endpoint ProtectionF-secure Internet Gatekeeper+123/9/202217/6/2026
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine
ModificadaMedia (6.7)0.34%—Ivanti Endpoint Manager23/9/202217/6/2026
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
ModificadaMedia (4.7)7.2%💥 PoCMicrosoft Windows Defender FOR Endpoint21/9/202217/6/2026
A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root…
ModificadaMedia (5.5)12%💥 PoCMicrosoft Windows Defender FOR Endpoint21/9/202217/6/2026
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.
ModificadaAlta (7.5)1.9%—Microsoft Endpoint Configuration Manager20/9/202217/6/2026
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
ModificadaAlta (7.8)0.53%—Microsoft Defender FOR Endpoint13/9/202217/6/2026
Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability