Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.37% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (6.5) | 1.1% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. | |
| Analizada | Crítica (9.1) | 0.86% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled… | |
| Analizada | Alta (7.2) | 2.5% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 1.5% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods. | |
| Analizada | Crítica (9.1) | 0.85% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Symantec Data Loss Prevention Windows EndpointAI | 30/3/2026 | 17/6/2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to… | |
| Pendiente de análisis | Media (6.7) | 0.16% | — | Netskope Endpoint DLP ModuleAINetskope ClientAI | 17/3/2026 | 17/6/2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would… | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | Netskope Endpoint DLP ModuleAINetskope ClientAI | 17/3/2026 | 17/6/2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filter communication port, leading to a Blue-Screen-of-Death (BSOD). Successful… | |
| Analizada | Crítica (9.3) | 0.86% | — | Motex Lanscope Endpoint Manager | 25/2/2026 | 17/6/2026 | Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system. | |
| Analizada | Alta (8.5) | 0.17% | — | Cyberark Endpoint Privilege Manager | 25/2/2026 | 17/6/2026 | CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs | |
| En análisis | Media (6.2) | 0.10% | — | Trellix Endpoint Security | 24/2/2026 | 17/6/2026 | A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security… | |
| Analizada | Alta (8.8) | 0.53% | — | Microsoft Defender FOR Endpoint | 10/2/2026 | 17/6/2026 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | |
| Analizada | Alta (7.5) | 88% | ⚠ Explotación activa | Ivanti Endpoint Manager | 10/2/2026 | 17/6/2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | |
| Analizada | Media (6.5) | 0.73% | — | Ivanti Endpoint Manager | 10/2/2026 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Analizada | Alta (7.8) | 0.19% | — | Tanium Endpoint Configuration Toolset SolutionTanium Patch Endpoint Tools | 10/2/2026 | 17/6/2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | |
| Analizada | Alta (7.8) | 0.19% | — | Tanium Patch Endpoint Tools | 9/2/2026 | 17/6/2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | |
| Aplazada | Alta (7.5) | 0.42% | — | Cisco Telepresence Collaboration EndpointAICisco RoomosAI | 4/2/2026 | 17/6/2026 | A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received… | |
| Modificada | Alta (7.8) | 0.26% | — | Cyberark Endpoint Privilege Manager | 3/2/2026 | 17/6/2026 | CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Aplazada | Media (4.4) | 0.15% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry. | |
| Aplazada | Media (6.7) | 0.17% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | |
| Aplazada | Media (6.9) | 0.27% | — | Freepbx Endpoint ManagerAI | 10/12/2025 | 25/9/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this… |