Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.57%—IBM Guardium Data EncryptionIBM Guardium FOR Cloud KEY Management26/8/202017/6/2026
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the…
ModificadaMedia (5.3)0.38%—IBM Guardium Data EncryptionIBM Guardium FOR Cloud KEY Management26/8/202017/6/2026
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the…
ModificadaAlta (7.8)0.18%—Dell EncryptionDell Endpoint Security Suite Enterprise18/8/202017/6/2026
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected…
ModificadaAlta (7.8)0.19%—Dell EncryptionDell Endpoint Security Suite Enterprise15/6/202017/6/2026
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the…
ModificadaAlta (7.8)0.32%—Symantec Encryption DesktopSymantec Endpoint EncryptionSymantec Ghost Solution SuiteSymantec IT Management Suite8/1/202017/6/2026
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x…
ModificadaAlta (7.3)0.29%—Dell EncryptionDell Endpoint Security Suite Enterprise7/10/201917/6/2026
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially…
ModificadaAlta (7.8)0.21%—Symantec Endpoint Encryption1/7/201917/6/2026
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
ModificadaAlta (7.8)0.21%—Symantec Endpoint Encryption1/7/201917/6/2026
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
ModificadaAlta (7.8)0.24%—Symantec Endpoint Encryption10/4/201917/6/2026
Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaAlta (7.8)0.28%—Winmagic Securedoc Disk Encryption8/4/201917/6/2026
WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system. If the executable is enclosed in quote tags "" then the system will know where to find it. However if the path of where the application binary…
ModificadaMedia (4.3)0.21%—Dell Data Protection | Encryption5/12/201817/6/2026
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.
ModificadaAlta (7.5)0.55%—Dell EncryptionDell Endpoint Security Suite Enterprise11/10/201817/6/2026
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially…
ModificadaMedia (5.3)0.41%—IBM Multi-cloud Data Encryption2/10/201817/6/2026
IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checksums. IBM X-Force ID: 143568.
ModificadaAlta (7.5)1.8%—Symantec Encryption Management Server20/8/201817/6/2026
The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or…
ModificadaMedia (6.6)0.24%—Mcafee Drive Encryption27/7/201817/6/2026
Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass local security protection via specific set of circumstances.
ModificadaAlta (7.8)0.61%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x802022E0. By crafting an input buffer we can control the execution path to the point where the constant 0x12 will be written to a user-controlled…
ModificadaAlta (7.8)0.61%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x8020601C. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled…
ModificadaAlta (7.8)0.54%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202014. By crafting an input buffer we can control the execution path to the point where the constant 0xFFFFFFF will be written to a user-controlled…
ModificadaAlta (7.8)0.60%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via multiple IOCTLs, e.g., 0x8810200B, 0x8810200F, 0x8810201B, 0x8810201F, 0x8810202B, 0x8810202F, 0x8810203F, 0x8810204B, 0x88102003, 0x88102007, 0x88102013,…
ModificadaAlta (7.8)0.61%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206024. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled…
ModificadaAlta (7.8)0.61%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202298. By crafting an input buffer we can control the execution path to the point where the nt!memset function is called to zero out contents of a…
ModificadaAlta (7.8)0.61%—Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client9/7/201817/6/2026
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206040. By crafting an input buffer we can control the execution path to the point where the constant DWORD 0 will be written to a user-controlled…
ModificadaAlta (8.8)2.3%—Totemo Encryption Gateway20/6/201817/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti-CSRF token.
ModificadaAlta (7.8)0.25%—Mcafee Management OF Native Encryption5/6/201817/6/2026
Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a crafted user input.
ModificadaAlta (8.8)9.8%—Trendmicro Email Encryption Gateway23/5/201817/6/2026
A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is required to exploit this vulnerability.