Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.17% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+1 | 10/12/2025 | 17/6/2026 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,… | |
| Analizada | Alta (7.8) | 0.58% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required. | |
| Analizada | Alta (8) | 1.4% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required. | |
| Analizada | Alta (8.8) | 2.0% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required. | |
| Analizada | Media (6.1) | 33% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required. | |
| Aplazada | Media (5.1) | 0.18% | — | Kaspersky Endpoint Security FOR LinuxAIKaspersky Industrial Cybersecurity FOR Linux NodesAIKaspersky Endpoint Security FOR MACAI | 20/11/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and… | |
| Analizada | Alta (7.1) | 0.24% | — | Ivanti Endpoint Manager | 11/11/2025 | 17/6/2026 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk | |
| Analizada | Media (6.8) | 0.10% | — | Bitdefender Endpoint Security | 11/11/2025 | 17/6/2026 | An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory… | |
| Analizada | Media (4.3) | 0.52% | — | Zohocorp Manageengine Endpoint Central | 27/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token. | |
| Analizada | Media (5.3) | 0.34% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. | |
| Analizada | Baja (3.3) | 0.26% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. | |
| Analizada | Crítica (9.3) | 2.8% | ⚠ Explotación activa | Motex Lanscope Endpoint Manager | 20/10/2025 | 17/6/2026 | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets. | |
| Analizada | Media (4.9) | 0.36% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/10/2025 | 17/6/2026 | A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid… | |
| Aplazada | Alta (8.6) | 44% | 💥 Exploit | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. The fwbrand… | |
| Aplazada | Alta (8.6) | 38% | 💥 Exploit | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model,… | |
| Aplazada | Alta (8.6) | 0.53% | — | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk… | |
| Analizada | Media (4.7) | 0.21% | — | Microsoft Defender FOR Endpoint | 14/10/2025 | 30/9/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. | |
| Analizada | Media (5.5) | 0.62% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 30/9/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Media (6.5) | 0.82% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 0.82% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 1.7% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 1.7% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |