Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.6%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
ModificadaAlta (7.5)5.1%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
ModificadaAlta (7.5)3.4%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
ModificadaAlta (7.8)1.6%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
ModificadaAlta (7.8)0.89%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.
ModificadaMedia (5.5)0.33%—Cisco Advanced Malware Protection FOR Endpoints22/5/202017/6/2026
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability…
ModificadaMedia (5.5)0.33%—Cisco Advanced Malware Protection FOR Endpoints22/5/202017/6/2026
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability…
ModificadaMedia (6.1)0.56%—Cisco Advanced Malware Protection FOR Endpoints22/5/202017/6/2026
A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP for Endpoints service. The vulnerability is due to…
ModificadaAlta (7.8)0.75%💥 PoCSymantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
ModificadaAlta (7.8)0.37%—Symantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.
ModificadaAlta (7)0.32%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.
ModificadaMedia (5.3)1.7%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.
ModificadaBaja (3.3)0.36%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaAlta (7.8)0.25%—Mcafee Endpoint Detection AND Response8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
ModificadaAlta (7.8)0.25%—Mcafee Endpoint Detection AND Response8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
ModificadaAlta (7.8)0.25%—Mcafee Endpoint Detection AND Response8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
ModificadaAlta (7.8)0.25%—Mcafee Mvision Endpoint8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.5.0.94 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
ModificadaAlta (8.4)0.26%—Mcafee Endpoint Security8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or…
ModificadaAlta (8.4)0.26%—Mcafee Endpoint Security8/5/202017/6/2026
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a…
ModificadaAlta (7.5)0.97%—Cososys Endpoint Protector4/5/202017/6/2026
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
ModificadaAlta (7.8)0.38%—Eset Antivirus AND AntispywareEset Endpoint AntivirusEset Endpoint SecurityEset File Security+429/4/202017/6/2026
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
ModificadaAlta (7.1)0.71%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection15/4/202017/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
ModificadaMedia (4.4)0.23%—Mcafee Endpoint Security15/4/202017/6/2026
Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock…
ModificadaAlta (7.8)0.39%—Mcafee Endpoint Security15/4/202017/6/2026
Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which the user which not normally have permission to alter via carefully creating…
ModificadaMedia (5.3)0.27%—Mcafee Endpoint Security15/4/202017/6/2026
Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.
Orbitaley — Vulnerabilidades