Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)1.2%—EMC RSA Data Loss Prevention3/5/201617/6/2026
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified parameter.
ModificadaMedia (4.3)1.6%—EMC RSA Data Loss Prevention3/5/201617/6/2026
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.
ModificadaMedia (6.1)1.5%—EMC RSA Data Loss Prevention3/5/201617/6/2026
Cross-site scripting (XSS) vulnerability in EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.1)1.1%💥 ExploitMcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+38/4/201617/6/2026
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before…
ModificadaMedia (6.8)1.0%—Symantec Data Loss Prevention28/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (4.3)2.0%—Symantec Data Loss Prevention28/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)1.1%—Mcafee Data Loss Prevention Endpoint27/3/201517/6/2026
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.82%—Mcafee Data Loss Prevention Endpoint27/3/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obtain sensitive information or (2) modify the database via…
ModificadaMedia (6.5)1.5%—Mcafee Data Loss Prevention Endpoint27/3/201517/6/2026
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.
ModificadaMedia (4)1.4%—Mcafee Data Loss Prevention Endpoint27/3/201517/6/2026
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors.
ModificadaMedia (4)1.3%—Mcafee Data Loss Prevention Endpoint17/2/201517/6/2026
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.
ModificadaBaja (3.5)1.1%—Mcafee Data Loss Prevention Endpoint17/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)1.4%—Mcafee Data Loss Prevention Endpoint17/2/201517/6/2026
SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.9)0.88%💥 ExploitMcafee Data Loss Prevention Endpoint6/2/201517/6/2026
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
ModificadaBaja (2.1)0.33%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.
ModificadaBaja (2.1)0.33%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages.
ModificadaMedia (4.6)0.32%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors.
ModificadaBaja (2.1)0.29%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
Unspecified vulnerability in the login form in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to cause a denial of service via a crafted value in the domain field.
ModificadaAlta (7.5)2.2%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.
ModificadaBaja (3.6)0.32%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
Unspecified vulnerability in McAfee Network Data Loss Prevention before (NDLP) before 9.3 allows local users to obtain sensitive information and impact integrity via unknown vectors, related to partition mounting.
ModificadaMedia (6.5)1.9%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
The TLS/SSL Server in McAfee Network Data Loss Prevention (NDLP) before 9.3 uses weak cipher algorithms, which makes it easier for remote authenticated users to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)1.3%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect integrity, or cause a denial of service via unknown vectors, related to simultaneous logins.
ModificadaBaja (2.1)0.32%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors.
ModificadaBaja (2.1)0.32%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.
ModificadaBaja (3.6)0.32%—Mcafee Network Data Loss Prevention29/10/201417/6/2026
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password."
Orbitaley — Vulnerabilidades