Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.4)0.22%—Ivanti Endpoint Manager8/7/202517/6/2026
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
AnalizadaAlta (8.4)0.22%—Ivanti Endpoint Manager8/7/202517/6/2026
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
AnalizadaAlta (7.2)17%—Ivanti Endpoint Manager Mobile8/7/202517/6/2026
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
AnalizadaAlta (8.8)87%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Mobile13/5/202517/6/2026
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Mobile13/5/202517/6/2026
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
AnalizadaCrítica (9.6)1.1%—Ivanti Endpoint Manager8/4/202517/6/2026
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
AnalizadaMedia (6.1)0.58%—Ivanti Endpoint Manager8/4/202517/6/2026
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.
AnalizadaMedia (6.1)0.24%—Ivanti Endpoint Manager8/4/202517/6/2026
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
AnalizadaAlta (7.2)1.3%—Ivanti Endpoint Manager8/4/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.
AnalizadaMedia (4.8)0.31%—Ivanti Endpoint Manager8/4/202517/6/2026
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
ModificadaAlta (7.8)0.40%—Ivanti Endpoint Manager8/4/202517/6/2026
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
AnalizadaAlta (7.8)0.51%—Ivanti Endpoint Manager14/1/202517/6/2026
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.8)18%—Ivanti Endpoint Manager14/1/202517/6/2026
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.5)2.7%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.8)0.44%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.4%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.8)0.38%—Ivanti Endpoint Manager14/1/202517/6/2026
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (7.8)9.2%—Ivanti Endpoint Manager14/1/202517/6/2026
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.2)64%—Ivanti Endpoint Manager14/1/202517/6/2026
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
AnalizadaAlta (7.5)90%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)91%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.