Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

613 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.6%—Mcafee Advanced Threat Defense12/7/201717/6/2026
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
ModificadaCrítica (9.8)3.4%—Mcafee Advanced Threat Defense12/7/201717/6/2026
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
ModificadaCrítica (9.8)2.1%—Mcafee Advanced Threat Defense12/7/201717/6/2026
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter.
ModificadaMedia (5.4)0.51%—Mcafee Data Loss Prevention Endpoint23/6/201717/6/2026
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
ModificadaAlta (7.8)2.7%💥 ExploitRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaMedia (6.5)7.2%—OpenldapDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+629/5/201717/6/2026
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
ModificadaAlta (7.2)2.8%—Mcafee Epolicy Orchestrator18/5/201717/6/2026
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header.
ModificadaMedia (4.5)1.2%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
ModificadaAlta (8)0.86%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.
ModificadaMedia (6.5)1.3%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request.
ModificadaMedia (6.1)3.3%💥 ExploitMcafee Network Data Loss Prevention17/5/201717/6/2026
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
ModificadaMedia (4.3)1.2%—Mcafee Virusscan Enterprise25/4/201717/6/2026
A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows remote attackers to create a Denial of Service on the active Internet Explorer tab via a crafted HTML link.
ModificadaAlta (7.3)0.29%—Mcafee Anti-malware Scan Engine31/3/201717/6/2026
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.
ModificadaAlta (7.3)0.36%—Mcafee Anti-malware Scan Engine28/3/201717/6/2026
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.
ModificadaMedia (6.5)1.7%—Mcafee Advanced Threat Defense14/3/201717/6/2026
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
ModificadaCrítica (10)5.7%—Mcafee Epolicy Orchestrator14/3/201717/6/2026
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted…
ModificadaAlta (7.8)0.44%—Mcafee Security Scan Plus14/3/201717/6/2026
Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.
ModificadaMedia (6.2)6.5%💥 ExploitMcafee Virusscan Enterprise14/3/201717/6/2026
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
ModificadaAlta (8.1)8.7%💥 ExploitMcafee Virusscan Enterprise14/3/201717/6/2026
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to obtain sensitive information via the server HTTP response spoofing.
ModificadaAlta (8.1)9.2%💥 ExploitMcafee Virusscan Enterprise14/3/201717/6/2026
Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to bypass server authentication via a crafted authentication cookie.
ModificadaAlta (7.5)13%💥 ExploitMcafee Virusscan Enterprise14/3/201717/6/2026
Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie.
ModificadaMedia (5)3.3%💥 ExploitMcafee Virusscan Enterprise14/3/201717/6/2026
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.
Orbitaley — Vulnerabilidades