Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.61%💥 PoCMicrosoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection25/2/202117/6/2026
Microsoft Defender Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)39%⚠ Explotación activa💥 PoCMicrosoft Windows DefenderMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection12/1/202117/6/2026
Microsoft Defender Remote Code Execution Vulnerability
ModificadaAlta (7.1)0.77%—Malwarebytes Endpoint ProtectionMalwarebytes22/12/202017/6/2026
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
ModificadaAlta (7.1)0.72%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection14/7/202017/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
ModificadaAlta (7.8)1.6%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
ModificadaAlta (7.8)0.89%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.
ModificadaAlta (7.8)0.75%💥 PoCSymantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
ModificadaAlta (7.8)0.37%—Symantec Endpoint Protection11/5/202017/6/2026
Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.
ModificadaAlta (7)0.32%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.
ModificadaMedia (5.3)1.7%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.
ModificadaBaja (3.3)0.36%—Symantec Endpoint Protection Manager11/5/202017/6/2026
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaAlta (7.1)0.71%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection15/4/202017/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
ModificadaAlta (7.8)0.97%—Sophos Cloud OptixSophos Endpoint ProtectionSophos Intercept X EndpointSophos Intercept X FOR Server+224/2/202017/6/2026
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because…
ModificadaBaja (3.3)0.35%—Symantec Endpoint Protection Manager11/2/202017/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaBaja (3.3)0.35%—Symantec Endpoint Protection Manager11/2/202017/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaBaja (3.3)0.35%—Symantec Endpoint Protection Manager11/2/202017/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaBaja (3.3)0.35%—Symantec Endpoint Protection Manager11/2/202017/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaBaja (3.3)0.35%—Symantec Endpoint Protection Manager11/2/202017/6/2026
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
ModificadaMedia (5.5)0.34%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the…
ModificadaMedia (5.5)0.36%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the…
ModificadaMedia (5.5)0.34%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a denial of service vulnerability, which is a type of issue whereby a threat actor attempts to tie up the resources of a resident…
ModificadaAlta (7.8)0.39%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software…
ModificadaAlta (7.8)0.39%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software…
ModificadaAlta (7.8)0.43%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to execute their own code in place of…
ModificadaAlta (7.8)0.39%—Symantec Endpoint Protection11/2/202017/6/2026
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software…
Orbitaley — Vulnerabilidades