Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.23%—Eset Cyber SecurityEset Endpoint AntivirusEset Endpoint Security8/11/202117/6/2026
ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.
ModificadaAlta (7.5)2.6%—Kaspersky Endpoint Security3/11/202117/6/2026
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
ModificadaAlta (7.8)0.69%—Bitdefender Endpoint Security ToolsBitdefender Total Security28/10/202117/6/2026
Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects: Bitdefender Endpoint Security Tools for Windows…
ModificadaAlta (7.8)0.96%—Bitdefender Endpoint Security ToolsBitdefender Total Security28/10/202117/6/2026
Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the client's security context. This issue…
ModificadaAlta (7.8)0.31%—Mcafee Endpoint Security17/9/202117/6/2026
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.
ModificadaMedia (5.5)0.23%—Mcafee Endpoint Security17/9/202117/6/2026
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.
ModificadaMedia (6.7)0.25%—Microfocus Zenworks Configuration ManagementMicrofocus Zenworks Endpoint Security Management30/7/202117/6/2026
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.
ModificadaMedia (6.7)0.25%—Stormshield Endpoint Security13/7/202117/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
ModificadaBaja (3.5)0.33%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.
ModificadaMedia (5.7)0.61%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.
ModificadaMedia (5.7)0.46%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.
ModificadaMedia (5.7)0.49%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.
ModificadaMedia (5.2)0.30%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
ModificadaAlta (7.3)0.33%—Stormshield Endpoint Security13/7/202117/6/2026
SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installed.
ModificadaMedia (6.6)0.88%—Bitdefender Endpoint Security Tools24/5/202117/6/2026
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux…
ModificadaBaja (3.3)0.47%—Bitdefender Endpoint Security Tools18/5/202117/6/2026
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.
ModificadaAlta (7)0.19%—Mcafee Endpoint Security FOR Linux Threat Prevention12/5/202117/6/2026
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through…
ModificadaMedia (6.5)0.51%—Mcafee Endpoint Security15/4/202117/6/2026
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an…
ModificadaMedia (6.8)0.23%—Kaspersky Endpoint SecurityKaspersky Rescue Disk26/2/202117/6/2026
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue…
ModificadaMedia (4.8)0.64%—Mcafee Endpoint Security10/2/202117/6/2026
A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the…
ModificadaMedia (4.4)0.27%—Mcafee Endpoint Security10/2/202117/6/2026
A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.
ModificadaMedia (4.4)0.29%—Mcafee Endpoint Security10/2/202117/6/2026
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the…
ModificadaMedia (4.4)0.29%—Mcafee Endpoint Security10/2/202117/6/2026
Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters.
ModificadaMedia (5)0.62%—Mcafee Endpoint Security10/2/202117/6/2026
Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the…
ModificadaMedia (5.5)0.33%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+426/1/202117/6/2026
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET…
Orbitaley — Vulnerabilidades