Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.6% | — | Mcafee Advanced Threat Defense | 12/7/2017 | 17/6/2026 | Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter. | |
| Modificada | Crítica (9.8) | 3.4% | — | Mcafee Advanced Threat Defense | 12/7/2017 | 17/6/2026 | Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter. | |
| Modificada | Crítica (9.8) | 2.1% | — | Mcafee Advanced Threat Defense | 12/7/2017 | 17/6/2026 | Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Firepower Threat DefenseCisco Secure Firewall Threat Defense | 22/5/2017 | 11/8/2026 | A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging… | |
| Modificada | Alta (8.8) | 0.57% | — | Symantec Content AnalysisSymantec Mail Threat Defense | 11/5/2017 | 17/6/2026 | The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an… | |
| Modificada | Alta (7.1) | 1.8% | — | Cisco Secure Firewall Threat Defense | 3/5/2017 | 11/8/2026 | A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a… | |
| Modificada | Media (5.9) | 1.3% | — | Cisco Secure Firewall Threat Defense | 7/4/2017 | 11/8/2026 | A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System… | |
| Modificada | Media (6.5) | 1.7% | — | Mcafee Advanced Threat Defense | 14/3/2017 | 17/6/2026 | SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Mcafee Advanced Threat Defense | 14/3/2017 | 17/6/2026 | Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware. | |
| Modificada | Media (5.5) | 0.73% | — | Mcafee Advanced Threat Defense | 14/3/2017 | 17/6/2026 | Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resulting in failure to detect a malware file (false-negative) via specially crafted… | |
| Modificada | Media (5.3) | 1.5% | — | Cisco Secure Firewall Threat Defense | 3/2/2017 | 11/8/2026 | A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable… | |
| Modificada | Media (5.3) | 0.35% | — | Cisco Secure Firewall Threat Defense | 3/2/2017 | 11/8/2026 | A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases:… | |
| Modificada | Alta (7.5) | 0.61% | — | Mcafee Advanced Threat Defense | 8/4/2016 | 17/6/2026 | McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process. | |
| Modificada | Media (4) | 0.95% | — | Mcafee Advanced Threat Defense | 8/4/2015 | 17/6/2026 | The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors. | |
| Modificada | Media (4) | 0.95% | — | Mcafee Advanced Threat Defense | 8/4/2015 | 17/6/2026 | The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.5) | 0.99% | — | Mcafee Advanced Threat Defense | 8/4/2015 | 17/6/2026 | McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted parameters. |