Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.2) | 0.28% | — | Stormshield Endpoint Security | 21/12/2021 | 17/6/2026 | Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. | |
| Modificada | Alta (7.5) | 0.21% | — | Fortinet ForticlientFortinet Forticlient Endpoint Management Server | 16/12/2021 | 17/6/2026 | A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Cloud Services Appliance | 8/12/2021 | 4/8/2026 | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | |
| Modificada | Media (5.5) | 0.41% | — | F-secure AtlantF-secure Internet GatekeeperF-secure Linux SecurityF-secure Linux Security 64+1 | 26/11/2021 | 17/6/2026 | A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine. | |
| Modificada | Media (4.4) | 0.25% | — | Sophos Exploit PreventionSophos Intercept X EndpointSophos Intercept X FOR Server | 26/11/2021 | 17/6/2026 | A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3. | |
| Modificada | Crítica (10) | 2.1% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390;… | |
| Modificada | Alta (7.5) | 1.3% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33.… | |
| Modificada | Alta (7.5) | 1.3% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone… | |
| Modificada | Alta (7.5) | 0.97% | — | Intel Endpoint Management Assistant | 17/11/2021 | 17/6/2026 | Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (5.5) | 0.23% | — | Eset Cyber SecurityEset Endpoint AntivirusEset Endpoint Security | 8/11/2021 | 17/6/2026 | ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot. | |
| Modificada | Alta (7.5) | 2.6% | — | Kaspersky Endpoint Security | 3/11/2021 | 17/6/2026 | Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable. | |
| Modificada | Alta (7.2) | 1.1% | — | Mcafee Data Loss Prevention Endpoint | 1/11/2021 | 17/6/2026 | SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension. | |
| Modificada | Media (6.1) | 0.81% | — | Mcafee Data Loss Prevention Endpoint | 1/11/2021 | 17/6/2026 | Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension. | |
| Modificada | Alta (7.8) | 0.69% | — | Bitdefender Endpoint Security ToolsBitdefender Total Security | 28/10/2021 | 17/6/2026 | Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects: Bitdefender Endpoint Security Tools for Windows… | |
| Modificada | Alta (7.8) | 0.96% | — | Bitdefender Endpoint Security ToolsBitdefender Total Security | 28/10/2021 | 17/6/2026 | Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the client's security context. This issue… | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus… | |
| Modificada | Baja (3.3) | 0.19% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 6/10/2021 | 17/6/2026 | A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a… | |
| Modificada | Crítica (9.8) | 3.9% | 💥 PoC | Fortinet Forticlient Endpoint Management Server | 6/10/2021 | 17/6/2026 | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks) | |
| Modificada | Media (5.4) | 1.1% | — | Fortinet Forticlient Endpoint Management Server | 6/10/2021 | 17/6/2026 | A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages. | |
| Modificada | Alta (7.3) | 0.38% | — | Mcafee Data Loss Prevention Endpoint | 17/9/2021 | 17/6/2026 | A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a… | |
| Modificada | Alta (7.8) | 0.31% | — | Mcafee Endpoint Security | 17/9/2021 | 17/6/2026 | Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location. | |
| Modificada | Media (5.5) | 0.23% | — | Mcafee Endpoint Security | 17/9/2021 | 17/6/2026 | XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process. | |
| Modificada | Media (5.5) | 0.41% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Linux SecurityF-secure Elements Endpoint Protection | 7/9/2021 | 17/6/2026 | A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine. | |
| Modificada | Media (6.5) | 0.74% | — | F-secure AtlantF-secure Linux SecurityF-secure Elements Endpoint Protection | 23/8/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… |