Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.53% | — | F-secure Client SecurityF-secure Linux SecurityF-secure Business SuiteF-secure Elements Endpoint Protection | 5/8/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine. | |
| Modificada | Media (6.7) | 0.25% | — | Microfocus Zenworks Configuration ManagementMicrofocus Zenworks Endpoint Security Management | 30/7/2021 | 17/6/2026 | A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges. | |
| Modificada | Media (6.7) | 0.25% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones. | |
| Modificada | Baja (3.5) | 0.33% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies. | |
| Modificada | Media (5.7) | 0.61% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.7) | 0.46% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.7) | 0.49% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (5.2) | 0.30% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies. | |
| Modificada | Alta (7.3) | 0.33% | — | Stormshield Endpoint Security | 13/7/2021 | 17/6/2026 | SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installed. | |
| Modificada | Media (6.5) | 0.68% | — | F-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Endpoint ProtectionF-secure Linux Security | 21/6/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (6.6) | 0.88% | — | Bitdefender Endpoint Security Tools | 24/5/2021 | 17/6/2026 | An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux… | |
| Modificada | Baja (3.3) | 0.47% | — | Bitdefender Endpoint Security Tools | 18/5/2021 | 17/6/2026 | An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research. | |
| Modificada | Media (5.3) | 0.79% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially gain access to a victim's web history. | |
| Modificada | Alta (7.3) | 0.96% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user. | |
| Modificada | Media (5.5) | 0.22% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially to prevent any new user connections. | |
| Modificada | Alta (7) | 0.19% | — | Mcafee Endpoint Security FOR Linux Threat Prevention | 12/5/2021 | 17/6/2026 | By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through… | |
| Modificada | Media (6.1) | 0.80% | — | Vmware Workspace ONE Unified Endpoint Management | 11/5/2021 | 17/6/2026 | VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 6/5/2021 | 17/6/2026 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability is due to insufficient path validation of command… | |
| Modificada | Alta (7.8) | 0.22% | — | Mcafee Data Loss Prevention Endpoint | 15/4/2021 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are… | |
| Modificada | Media (5.5) | 0.22% | — | Mcafee Data Loss Prevention Endpoint | 15/4/2021 | 17/6/2026 | Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory. | |
| Modificada | Media (6.5) | 0.51% | — | Mcafee Endpoint Security | 15/4/2021 | 17/6/2026 | Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an… | |
| Modificada | Alta (7.8) | 0.28% | — | Cisco Advanced Malware Protection FOR EndpointsCisco ClamavCisco Immunet | 8/4/2021 | 17/6/2026 | A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected Windows system. To exploit this vulnerability,… | |
| Modificada | Media (6.7) | 0.34% | — | Mcafee Endpoint Product Removal Tool | 15/3/2021 | 17/6/2026 | Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path. Local admin privileges are required to… | |
| Modificada | Media (6.8) | 0.23% | — | Kaspersky Endpoint SecurityKaspersky Rescue Disk | 26/2/2021 | 17/6/2026 | A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue… | |
| Modificada | Alta (7.8) | 0.61% | 💥 PoC | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection | 25/2/2021 | 17/6/2026 | Microsoft Defender Elevation of Privilege Vulnerability |