Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.64% | — | Mcafee Endpoint Security | 10/2/2021 | 17/6/2026 | A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the… | |
| Modificada | Media (4.4) | 0.27% | — | Mcafee Endpoint Security | 10/2/2021 | 17/6/2026 | A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update. | |
| Modificada | Media (4.4) | 0.29% | — | Mcafee Endpoint Security | 10/2/2021 | 17/6/2026 | Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the… | |
| Modificada | Media (4.4) | 0.29% | — | Mcafee Endpoint Security | 10/2/2021 | 17/6/2026 | Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters. | |
| Modificada | Media (5) | 0.62% | — | Mcafee Endpoint Security | 10/2/2021 | 17/6/2026 | Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the… | |
| Modificada | Media (5.5) | 0.33% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+4 | 26/1/2021 | 17/6/2026 | A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET… | |
| Modificada | Alta (7.3) | 0.44% | — | Cisco Advanced Malware Protection FOR EndpointsCisco Immunet | 20/1/2021 | 17/6/2026 | A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need valid credentials on the Windows… | |
| Analizada | Alta (7.8) | 39% | ⚠ Explotación activa💥 PoC | Microsoft Windows DefenderMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection | 12/1/2021 | 17/6/2026 | Microsoft Defender Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 0.77% | — | Malwarebytes Endpoint ProtectionMalwarebytes | 22/12/2020 | 17/6/2026 | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. | |
| Modificada | Alta (7.8) | 0.30% | — | Checkpoint Endpoint Security | 3/12/2020 | 17/6/2026 | Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair… | |
| Modificada | Media (5.5) | 0.44% | — | Cyberark Endpoint Privilege Manager | 27/11/2020 | 17/6/2026 | CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database. | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Symantec Endpoint Detection AND Response | 18/11/2020 | 17/6/2026 | Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Modificada | Media (6.5) | 0.73% | — | Cisco RoomosCisco Telepresence Collaboration Endpoint | 18/11/2020 | 17/6/2026 | A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI… | |
| Modificada | Media (5.4) | 1.3% | — | Ivanti Endpoint Manager | 16/11/2020 | 17/6/2026 | Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and /LDMS/query_browsecomp.aspx. | |
| Modificada | Media (5.3) | 2.3% | — | Ivanti Endpoint Manager | 16/11/2020 | 17/6/2026 | In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required. | |
| Modificada | Alta (8.8) | 2.7% | — | Ivanti Endpoint Manager | 16/11/2020 | 17/6/2026 | LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request. | |
| Modificada | Crítica (9.9) | 5.0% | — | Ivanti Endpoint Manager | 12/11/2020 | 17/6/2026 | An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx file. The issue is caused by insufficient file extension validation and insecure file operations on the uploaded image,… | |
| Modificada | Media (5.5) | 0.28% | — | Intel Endpoint Management Assistant | 12/11/2020 | 17/6/2026 | Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Intel Endpoint Management Assistant | 12/11/2020 | 17/6/2026 | Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.8) | 0.78% | — | Ivanti Endpoint Manager | 12/11/2020 | 17/6/2026 | Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable component such as NT AUTHORITY\SYSTEM) via… | |
| Modificada | Alta (7.8) | 0.47% | — | Ivanti Endpoint Manager | 12/11/2020 | 17/6/2026 | Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg.… | |
| Modificada | Media (4.8) | 0.52% | — | Mcafee Endpoint Security | 12/11/2020 | 17/6/2026 | Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML via the configuration wizard. | |
| Modificada | Alta (8.8) | 0.59% | — | Mcafee Endpoint Security | 12/11/2020 | 17/6/2026 | Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration. | |
| Modificada | Alta (7.8) | 0.42% | — | Mcafee Endpoint Security | 12/11/2020 | 17/6/2026 | Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files. | |
| Modificada | Alta (7.2) | 1.7% | — | Mcafee Mvision Endpoint | 11/11/2020 | 17/6/2026 | Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator. |