Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.41% | — | Stormshield Endpoint Security | 31/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | |
| Modificada | Media (5.5) | 0.15% | — | Stormshield Endpoint Security | 30/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | |
| Modificada | Alta (7.8) | 0.26% | — | Elastic EndgameElastic Endpoint Security | 8/2/2023 | 17/6/2026 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | |
| Modificada | Media (5.9) | 16% | — | OpensslStormshield Endpoint SecurityStormshield SslvpnStormshield Network Security | 8/2/2023 | 17/6/2026 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The… | |
| Modificada | Alta (7.8) | 0.26% | — | Elastic Endpoint Security | 26/1/2023 | 17/6/2026 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | |
| Modificada | Alta (7.8) | 0.24% | — | Elastic EndgameElastic Endpoint Security | 26/1/2023 | 17/6/2026 | An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | |
| Modificada | Media (6) | 0.23% | — | Trellix Endpoint Security | 16/12/2022 | 17/6/2026 | Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality. | |
| Modificada | Baja (2.3) | 4.6% | — | Checkpoint Endpoint SecurityCheckpoint Harmony Endpoint | 7/7/2022 | 17/6/2026 | Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator. | |
| Modificada | Alta (7.8) | 0.23% | — | Elastic Endpoint Security | 6/7/2022 | 17/6/2026 | A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | |
| Modificada | Alta (7.8) | 4.2% | — | Checkpoint Endpoint Security | 12/5/2022 | 17/6/2026 | Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. | |
| Modificada | Alta (7.8) | 0.21% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 11/5/2022 | 17/6/2026 | Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet… | |
| Modificada | Alta (7.1) | 0.19% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 10/5/2022 | 17/6/2026 | Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security… | |
| Modificada | Alta (7.5) | 1.2% | — | Bitdefender Endpoint Security ToolsBitdefender GravityzoneBitdefender Update Server | 7/4/2022 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276.… | |
| Modificada | Crítica (9.8) | 3.1% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies). | |
| Modificada | Media (5.5) | 0.20% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil,… | |
| Modificada | Alta (7.8) | 0.76% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security | 7/3/2022 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender… | |
| Modificada | Media (6.1) | 0.55% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security+1 | 7/3/2022 | 17/6/2026 | A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total… | |
| Modificada | Alta (7.8) | 0.60% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 9/2/2022 | 17/6/2026 | ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.8) | 0.57% | — | Checkpoint Endpoint Security | 10/1/2022 | 17/6/2026 | Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges. | |
| Modificada | Media (4.3) | 0.55% | — | Stormshield Endpoint Security | 21/12/2021 | 17/6/2026 | Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 2.9% | — | Stormshield Endpoint Security | 21/12/2021 | 17/6/2026 | Stormshield Endpoint Security before 2.1.2 allows remote code execution. | |
| Modificada | Media (5.2) | 0.28% | — | Stormshield Endpoint Security | 21/12/2021 | 17/6/2026 | Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. | |
| Modificada | Crítica (10) | 2.1% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390;… | |
| Modificada | Alta (7.5) | 1.3% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33.… | |
| Modificada | Alta (7.5) | 1.3% | — | Bitdefender Endpoint Security ToolsBitdefender Gravityzone | 24/11/2021 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone… |