Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.53%—Mcafee Data Loss Prevention14/11/201917/6/2026
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
ModificadaMedia (5.5)0.25%—Mcafee Data Loss Prevention Endpoint21/8/201917/6/2026
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory.
ModificadaMedia (5.5)0.25%—Mcafee Data Loss Prevention Endpoint21/8/201917/6/2026
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory.
ModificadaMedia (6.2)0.35%—Mcafee Data Loss Prevention Endpoint25/7/201917/6/2026
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to…
ModificadaAlta (8.2)0.33%—Mcafee Data Loss Prevention Endpoint24/7/201917/6/2026
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.
ModificadaMedia (6.5)0.71%—Mcafee Data Loss Prevention Endpoint24/7/201917/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened…
ModificadaMedia (6.1)0.83%—Mcafee Data Loss Prevention Endpoint24/7/201917/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote…
ModificadaMedia (4.8)1.8%💥 ExploitSymantec Data Loss Prevention19/6/201917/6/2026
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the…
ModificadaAlta (7.8)0.36%—Mcafee Data Loss Prevention Endpoint3/10/201817/6/2026
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
ModificadaAlta (7.4)0.30%—Mcafee Data Loss Prevention Endpoint23/7/201817/6/2026
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.
ModificadaCrítica (9.1)1.5%—Mcafee Network Data Loss PreventionMcafee Network Security Manager13/6/201817/6/2026
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
ModificadaAlta (8.8)0.71%—Mcafee Data Loss Prevention Endpoint25/5/201817/6/2026
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.
ModificadaAlta (7.5)1.0%—Mcafee Network Data Loss Prevention31/10/201717/6/2026
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type.
ModificadaMedia (5.9)0.99%—Mcafee Network Data Loss Prevention31/10/201717/6/2026
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.
ModificadaMedia (5.4)0.64%—Mcafee Network Data Loss Prevention31/10/201717/6/2026
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
ModificadaMedia (5.4)0.51%—Mcafee Data Loss Prevention Endpoint23/6/201717/6/2026
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header.
ModificadaMedia (4.5)1.2%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
ModificadaAlta (8)0.86%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
ModificadaMedia (5.3)1.0%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.
ModificadaMedia (6.5)1.3%—Mcafee Network Data Loss Prevention17/5/201717/6/2026
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request.
ModificadaMedia (6.1)3.3%💥 ExploitMcafee Network Data Loss Prevention17/5/201717/6/2026
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
ModificadaAlta (7.8)0.31%—Mcafee Data Loss Prevention Endpoint14/3/201717/6/2026
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get.
ModificadaMedia (4.3)1.2%—EMC RSA Data Loss Prevention3/5/201617/6/2026
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to conduct clickjacking attacks via web-site elements with crafted transparency or opacity.
Orbitaley — Vulnerabilidades