Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.22% | — | Ivanti Endpoint Manager | 8/7/2025 | 17/6/2026 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords. | |
| Analizada | Alta (8.4) | 0.22% | — | Ivanti Endpoint Manager | 8/7/2025 | 17/6/2026 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords. | |
| Analizada | Alta (7.2) | 17% | — | Ivanti Endpoint Manager Mobile | 8/7/2025 | 17/6/2026 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution | |
| Analizada | Alta (8.8) | 87% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | |
| Analizada | Crítica (9.6) | 1.1% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. | |
| Analizada | Media (6.1) | 0.58% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required. | |
| Analizada | Media (6.1) | 0.24% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition. | |
| Analizada | Alta (7.2) | 1.3% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution. | |
| Analizada | Media (4.8) | 0.31% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers. | |
| Modificada | Alta (7.8) | 0.40% | — | Ivanti Endpoint Manager | 8/4/2025 | 17/6/2026 | DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System. | |
| Analizada | Alta (7.8) | 0.51% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.8) | 18% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.5) | 2.7% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.44% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.4% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (7.8) | 9.2% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.2) | 64% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848. | |
| Analizada | Alta (7.5) | 90% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 91% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |