Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.28% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool. | |
| Modificada | Media (5.3) | 0.31% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to execute arbitrary code via a carefully crafted input file. | |
| Modificada | Alta (7.8) | 0.23% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's… | |
| Modificada | Media (5.5) | 0.25% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters. | |
| Modificada | Media (5.5) | 0.26% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Buffer Overflow via Environment Variables vulnerability in AMSI component in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to disable Endpoint Security via a carefully crafted user input. | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file | |
| Modificada | Media (6.3) | 0.25% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links whilst an anti-virus scan was in progress. This… | |
| Modificada | Media (6.5) | 0.64% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled… | |
| Modificada | Media (6.7) | 0.17% | — | Mcafee Endpoint Security | 1/4/2020 | 17/6/2026 | Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import. | |
| Modificada | Alta (7.8) | 0.97% | — | Sophos Cloud OptixSophos Endpoint ProtectionSophos Intercept X EndpointSophos Intercept X FOR Server+2 | 24/2/2020 | 17/6/2026 | The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because… | |
| Modificada | Alta (7.8) | 8.1% | — | IBM DominoIBM NotesSymantec Data Loss Prevention EndpointSymantec Data Loss Prevention Enforce/detection Servers+3 | 21/2/2020 | 16/6/2026 | Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus… | |
| Modificada | Alta (7) | 1.9% | — | Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+4 | 20/2/2020 | 17/6/2026 | Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by… | |
| Modificada | Media (5.5) | 2.9% | — | Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+4 | 20/2/2020 | 17/6/2026 | Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform… | |
| Modificada | Media (5.4) | 0.76% | — | IBM Tivoli Endpoint Manager | 18/2/2020 | 16/6/2026 | IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies. | |
| Modificada | Media (5.5) | 0.21% | — | Mcafee Endpoint Security | 14/2/2020 | 17/6/2026 | Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS. | |
| Modificada | Baja (3.3) | 0.35% | — | Symantec Endpoint Protection Manager | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Baja (3.3) | 0.35% | — | Symantec Endpoint Protection Manager | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Baja (3.3) | 0.35% | — | Symantec Endpoint Protection Manager | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Baja (3.3) | 0.35% | — | Symantec Endpoint Protection Manager | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Baja (3.3) | 0.35% | — | Symantec Endpoint Protection Manager | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | |
| Modificada | Media (5.5) | 0.34% | — | Symantec Endpoint Protection | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the… | |
| Modificada | Media (5.5) | 0.36% | — | Symantec Endpoint Protection | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the… | |
| Modificada | Media (5.5) | 0.34% | — | Symantec Endpoint Protection | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a denial of service vulnerability, which is a type of issue whereby a threat actor attempts to tie up the resources of a resident… | |
| Modificada | Alta (7.8) | 0.39% | — | Symantec Endpoint Protection | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software… | |
| Modificada | Alta (7.8) | 0.39% | — | Symantec Endpoint Protection | 11/2/2020 | 17/6/2026 | Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software… |