Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Management OF Native Encryption | 5/6/2018 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a crafted user input. | |
| Modificada | Baja (3.9) | 0.18% | — | Mcafee Virusscan Enterprise | 25/5/2018 | 17/6/2026 | Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current… | |
| Modificada | Alta (8.8) | 0.71% | — | Mcafee Data Loss Prevention Endpoint | 25/5/2018 | 17/6/2026 | Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility. | |
| Modificada | Media (5.4) | 0.61% | — | Mcafee Network Security Manager | 25/5/2018 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes. | |
| Modificada | Crítica (9.8) | 3.8% | — | Mcafee Tunnelbear | 26/4/2018 | 17/6/2026 | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server… | |
| Modificada | Media (6.5) | 0.31% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. | |
| Modificada | Media (5.9) | 0.80% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL. | |
| Modificada | Media (6.1) | 0.73% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames. | |
| Modificada | Media (6.3) | 0.67% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL. | |
| Modificada | Alta (8.8) | 0.54% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs. | |
| Modificada | Media (5.4) | 0.59% | — | Mcafee Network Security Manager | 4/4/2018 | 17/6/2026 | Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter. | |
| Modificada | Media (4.4) | 0.53% | — | Mcafee Anti-virus PlusMcafee Endpoint SecurityMcafee Host Intrusion PreventionMcafee Internet Security+2 | 3/4/2018 | 17/6/2026 | Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mcafee Network Security Manager | 3/4/2018 | 17/6/2026 | Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information. | |
| Modificada | Media (5.4) | 1.0% | — | Mcafee Epolicy Orchestrator | 2/4/2018 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input. | |
| Modificada | Alta (7.8) | 0.80% | — | Mcafee True KEY | 2/4/2018 | 17/6/2026 | DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not verifying a particular DLL file signature. | |
| Modificada | Media (4.9) | 1.7% | — | Mcafee Epolicy Orchestrator | 2/4/2018 | 17/6/2026 | Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file. | |
| Modificada | Alta (7.5) | 7.0% | — | OpenldapOpensuse LeapOracle Blockchain PlatformMcafee Policy Auditor | 18/12/2017 | 17/6/2026 | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation. | |
| Modificada | Alta (7.5) | 1.0% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type. | |
| Modificada | Media (5.9) | 0.99% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver. | |
| Modificada | Media (5.4) | 0.64% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack. | |
| Modificada | Media (5.9) | 3.2% | 💥 Exploit | Mcafee Livesafe | 1/9/2017 | 17/6/2026 | A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Mcafee LivesafeMcafee Security Scan Plus | 1/9/2017 | 17/6/2026 | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response. | |
| Modificada | Alta (7.5) | 11% | — | NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+10 | 7/8/2017 | 17/6/2026 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | |
| Modificada | Alta (8.8) | 1.2% | — | Mcafee Advanced Threat Defense | 12/7/2017 | 17/6/2026 | Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands. | |
| Modificada | Alta (7.5) | 1.4% | — | Mcafee Advanced Threat Defense | 12/7/2017 | 17/6/2026 | Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization. |