Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.2% | — | Mcafee Mvision Endpoint | 11/11/2020 | 17/6/2026 | External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO… | |
| Modificada | Media (4.3) | 0.85% | — | Cisco Telepresence Collaboration Endpoint | 6/11/2020 | 17/6/2026 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive information on an affected device. An… | |
| Modificada | Media (5.5) | 0.34% | — | Checkpoint Endpoint Security | 5/11/2020 | 17/6/2026 | Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations. | |
| Modificada | Media (6.5) | 0.39% | — | Checkpoint Endpoint Security | 2/11/2020 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies… | |
| Modificada | Media (6.7) | 0.29% | — | Mcafee Mvision Endpoint Detection AND Response | 15/10/2020 | 17/6/2026 | Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than… | |
| Modificada | Media (5.5) | 0.27% | — | Blackberry Unified Endpoint Manager | 14/10/2020 | 17/6/2026 | An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco RoomosCisco Telepresence Collaboration Endpoint | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to insufficient input validation. An attacker could… | |
| Modificada | Alta (7.8) | 0.33% | — | Mcafee Mvision Endpoint | 9/9/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file. | |
| Modificada | Media (6.1) | 0.25% | — | Mcafee Mvision Endpoint | 9/9/2020 | 17/6/2026 | Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions. | |
| Modificada | Media (6.9) | 0.33% | — | Mcafee Endpoint Security | 9/9/2020 | 17/6/2026 | Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated… | |
| Modificada | Media (4.7) | 0.25% | — | Mcafee Endpoint Security | 9/9/2020 | 17/6/2026 | Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs. | |
| Modificada | Alta (7.3) | 0.26% | — | Mcafee Endpoint Security | 9/9/2020 | 17/6/2026 | Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services. | |
| Modificada | Alta (8.8) | 0.39% | — | Mcafee Endpoint Security | 9/9/2020 | 17/6/2026 | Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file. | |
| Modificada | Alta (7.8) | 0.42% | — | Bitdefender Endpoint SecurityBitdefender Endpoint Security Tools | 30/8/2020 | 17/6/2026 | An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tamper with the product's security settings. This issue affects: Bitdefender Endpoint Security Tools for Windows versions… | |
| Modificada | Alta (7.8) | 0.18% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 18/8/2020 | 17/6/2026 | Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected… | |
| Modificada | Alta (8.8) | 0.29% | — | Bitdefender Endpoint Security | 3/8/2020 | 17/6/2026 | Improper Authentication vulnerability in Bitdefender Endpoint Security for Mac allows an unprivileged process to restart the main service and potentially inject third-party code into a trusted process. This issue affects: Bitdefender Endpoint Security for Mac versions prior to 4.12.80. | |
| Modificada | Alta (7.1) | 0.72% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/7/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Symantec Endpoint Detection AND Response | 8/7/2020 | 17/6/2026 | Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Modificada | Media (6.3) | 0.26% | — | Cisco Advanced Malware Protection FOR EndpointsCisco Clam AntivirusFedoraproject FedoraDebian Linux+1 | 18/6/2020 | 17/6/2026 | A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local… | |
| Modificada | Alta (7.2) | 2.1% | — | Cisco RoomosCisco Telepresence Collaboration Endpoint | 18/6/2020 | 17/6/2026 | A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to… | |
| Modificada | Alta (7.8) | 0.19% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 15/6/2020 | 17/6/2026 | Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the… | |
| Modificada | Alta (7.8) | 0.50% | — | Webroot Endpoint Agents | 15/6/2020 | 17/6/2026 | Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation. | |
| Modificada | Crítica (9.1) | 1.5% | — | Webroot Endpoint Agents | 15/6/2020 | 17/6/2026 | Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent. | |
| Modificada | Alta (7.5) | 3.1% | — | IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+6 | 10/6/2020 | 17/6/2026 | Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+6 | 10/6/2020 | 17/6/2026 | Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901. |