Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.53% | — | Mcafee Data Loss Prevention | 14/11/2019 | 17/6/2026 | Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity. | |
| Modificada | Media (5.5) | 0.25% | — | Mcafee Data Loss Prevention Endpoint | 21/8/2019 | 17/6/2026 | Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory. | |
| Modificada | Media (5.5) | 0.25% | — | Mcafee Data Loss Prevention Endpoint | 21/8/2019 | 17/6/2026 | Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory. | |
| Modificada | Media (6.2) | 0.35% | — | Mcafee Data Loss Prevention Endpoint | 25/7/2019 | 17/6/2026 | Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to… | |
| Modificada | Alta (8.2) | 0.33% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links. | |
| Modificada | Media (6.5) | 0.71% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened… | |
| Modificada | Media (6.1) | 0.83% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote… | |
| Modificada | Media (4.8) | 1.8% | 💥 Exploit | Symantec Data Loss Prevention | 19/6/2019 | 17/6/2026 | DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the… | |
| Modificada | Alta (7.8) | 0.36% | — | Mcafee Data Loss Prevention Endpoint | 3/10/2018 | 17/6/2026 | Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions. | |
| Modificada | Alta (7.4) | 0.30% | — | Mcafee Data Loss Prevention Endpoint | 23/7/2018 | 17/6/2026 | Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline. | |
| Modificada | Crítica (9.1) | 1.5% | — | Mcafee Network Data Loss PreventionMcafee Network Security Manager | 13/6/2018 | 17/6/2026 | Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie. | |
| Modificada | Alta (8.8) | 0.71% | — | Mcafee Data Loss Prevention Endpoint | 25/5/2018 | 17/6/2026 | Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility. | |
| Modificada | Alta (7.5) | 1.0% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type. | |
| Modificada | Media (5.9) | 0.99% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver. | |
| Modificada | Media (5.4) | 0.64% | — | Mcafee Network Data Loss Prevention | 31/10/2017 | 17/6/2026 | Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack. | |
| Modificada | Media (5.4) | 0.51% | — | Mcafee Data Loss Prevention Endpoint | 23/6/2017 | 17/6/2026 | Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session. | |
| Modificada | Media (5.3) | 1.0% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface. | |
| Modificada | Media (5.3) | 1.0% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header. | |
| Modificada | Media (4.5) | 1.2% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header. | |
| Modificada | Alta (8) | 0.86% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request. | |
| Modificada | Media (5.3) | 1.0% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header. | |
| Modificada | Media (6.5) | 1.3% | — | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Mcafee Network Data Loss Prevention | 17/5/2017 | 17/6/2026 | Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request. | |
| Modificada | Alta (7.8) | 0.31% | — | Mcafee Data Loss Prevention Endpoint | 14/3/2017 | 17/6/2026 | Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get. | |
| Modificada | Media (4.3) | 1.2% | — | EMC RSA Data Loss Prevention | 3/5/2016 | 17/6/2026 | EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to conduct clickjacking attacks via web-site elements with crafted transparency or opacity. |