Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.37%—Ivanti Endpoint Manager12/5/202617/6/2026
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
AnalizadaMedia (6.5)1.1%—Ivanti Endpoint Manager12/5/202617/6/2026
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
AnalizadaCrítica (9.1)0.86%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled…
AnalizadaAlta (7.2)2.5%⚠ Explotación activaIvanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
AnalizadaCrítica (9.8)1.5%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
AnalizadaCrítica (9.1)0.85%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
AnalizadaAlta (8.8)1.2%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
Pendiente de análisisAlta (7.8)0.16%—Symantec Data Loss Prevention Windows EndpointAI30/3/202617/6/2026
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to…
Pendiente de análisisMedia (6.7)0.16%—Netskope Endpoint DLP ModuleAINetskope ClientAI17/3/202617/6/2026
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would…
Pendiente de análisisMedia (6.8)0.11%—Netskope Endpoint DLP ModuleAINetskope ClientAI17/3/202617/6/2026
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filter communication port, leading to a Blue-Screen-of-Death (BSOD). Successful…
AnalizadaCrítica (9.3)0.86%—Motex Lanscope Endpoint Manager25/2/202617/6/2026
Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.
AnalizadaAlta (8.5)0.17%—Cyberark Endpoint Privilege Manager25/2/202617/6/2026
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs
En análisisMedia (6.2)0.10%—Trellix Endpoint Security24/2/202617/6/2026
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security…
AnalizadaAlta (8.8)0.53%—Microsoft Defender FOR Endpoint10/2/202617/6/2026
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
AnalizadaAlta (7.5)88%⚠ Explotación activaIvanti Endpoint Manager10/2/202617/6/2026
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
AnalizadaMedia (6.5)0.73%—Ivanti Endpoint Manager10/2/202617/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
AnalizadaAlta (7.8)0.19%—Tanium Endpoint Configuration Toolset SolutionTanium Patch Endpoint Tools10/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
AnalizadaAlta (7.8)0.19%—Tanium Patch Endpoint Tools9/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
AplazadaAlta (7.5)0.42%—Cisco Telepresence Collaboration EndpointAICisco RoomosAI4/2/202617/6/2026
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received…
ModificadaAlta (7.8)0.26%—Cyberark Endpoint Privilege Manager3/2/202617/6/2026
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.
AnalizadaCrítica (9.8)99%⚠ Explotación activaIvanti Endpoint Manager Mobile29/1/202617/6/2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
AnalizadaCrítica (9.8)99%⚠ Explotación activaIvanti Endpoint Manager Mobile29/1/202617/6/2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
AplazadaMedia (4.4)0.15%—Symantec Endpoint ProtectionAI28/1/202617/6/2026
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.
AplazadaMedia (6.7)0.17%—Symantec Endpoint ProtectionAI28/1/202617/6/2026
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…
AplazadaMedia (6.9)0.27%—Freepbx Endpoint ManagerAI10/12/202525/9/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this…