Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 2.1% | — | Mcafee WEB Gateway | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port. | |
| Modificada | Media (6.3) | 2.0% | — | Mcafee Epolicy Orchestrator | 26/2/2014 | 17/6/2026 | The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Mcafee Vulnerability Manager | 28/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter. | |
| Modificada | Media (4.3) | 4.3% | 💥 Exploit | Mcafee Superscan | 21/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, which is not properly handled in the SuperScan HTML report. | |
| Modificada | Media (6.8) | 0.69% | — | Mcafee Vulnerability Manager | 16/1/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to hijack the authentication of users for requests that modify HTML via unspecified vectors related to the "response web page." | |
| Modificada | Media (4.3) | 2.0% | — | Mcafee Vulnerability Manager | 16/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9) | 3.9% | — | Mcafee Email Gateway | 14/12/2013 | 17/6/2026 | McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands. | |
| Modificada | Alta (9) | 3.9% | — | Mcafee Email Gateway | 14/12/2013 | 17/6/2026 | McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands. | |
| Modificada | Media (6.5) | 1.7% | — | Mcafee Email Gateway | 13/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) event_id, (3) reason, (4) events_order, (5) emailstatus_order, or (6) emailstatus_col JSON keys. | |
| Modificada | Alta (8.5) | 2.5% | — | Mcafee Email Gateway | 2/11/2013 | 17/6/2026 | McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 2.0% | — | Mcafee Agent | 5/10/2013 | 16/6/2026 | FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to cause a denial of service (service crash) via a malformed HTTP request. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Mcafee Epolicy OrchestratorMcafee Epolicy Orchestrator Agent | 22/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl… | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Mcafee Epolicy OrchestratorMcafee Epolicy Orchestrator Agent | 22/7/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2)… | |
| Modificada | Media (4.3) | 1.1% | — | Mcafee Epolicy Orchestrator | 1/5/2013 | 16/6/2026 | Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory. | |
| Modificada | Alta (7.9) | 2.5% | 💥 Exploit | Mcafee Epolicy Orchestrator | 1/5/2013 | 16/6/2026 | SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel. | |
| Modificada | Alta (8.2) | 5.2% | 💥 Exploit | Mcafee Virtual TechnicianEPO Mcafee Virtual Technician | 28/3/2013 | 16/6/2026 | An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or create arbitrary files via a full pathname argument to the Save method. | |
| Modificada | Alta (7.8) | 1.9% | — | Mcafee Email AND WEB Security | 25/9/2012 | 16/6/2026 | Unspecified vulnerability in McAfee Email Anti-virus (formerly WebShield SMTP) allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (6.2) | 0.30% | — | Mcafee Total Protection 2010 | 25/8/2012 | 16/6/2026 | Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Alta (10) | 3.9% | — | Mcafee Smartfilter Administration | 22/8/2012 | 16/6/2026 | McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file. | |
| Modificada | Alta (9.3) | 29% | 💥 Exploit | Mcafee Virtual TechnicianEPO Mcafee Virtual Technician | 22/8/2012 | 16/6/2026 | An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause a denial of service (Internet Explorer crash) via a crafted web site. | |
| Modificada | Media (4.3) | 1.1% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard. | |
| Modificada | Media (4.3) | 2.6% | — | Mcafee Email Gateway | 22/8/2012 | 16/6/2026 | Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL. | |
| Modificada | Alta (7.5) | 2.5% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors. | |
| Modificada | Media (4) | 0.97% | — | Mcafee Epolicy Orchestrator | 22/8/2012 | 16/6/2026 | McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL. | |
| Modificada | Media (5) | 0.99% | — | Mcafee Application ControlMcafee Change Control | 22/8/2012 | 16/6/2026 | McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attributes of the password file, which allows local users to bypass authentication by executing a command. |