Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.17%—Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+110/12/202517/6/2026
A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,…
AnalizadaAlta (7.8)0.58%—Ivanti Endpoint Manager9/12/202517/6/2026
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.
AnalizadaAlta (8)1.4%—Ivanti Endpoint Manager9/12/202517/6/2026
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
AnalizadaAlta (8.8)2.0%—Ivanti Endpoint Manager9/12/202517/6/2026
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
AnalizadaMedia (6.1)33%—Ivanti Endpoint Manager9/12/202517/6/2026
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
AplazadaMedia (5.1)0.18%—Kaspersky Endpoint Security FOR LinuxAIKaspersky Industrial Cybersecurity FOR Linux NodesAIKaspersky Endpoint Security FOR MACAI20/11/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and…
AnalizadaAlta (7.1)0.24%—Ivanti Endpoint Manager11/11/202517/6/2026
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
AnalizadaMedia (6.8)0.10%—Bitdefender Endpoint Security11/11/202517/6/2026
An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory…
AnalizadaMedia (4.3)0.52%—Zohocorp Manageengine Endpoint Central27/10/202517/6/2026
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
AnalizadaMedia (5.3)0.34%—Zohocorp Manageengine Endpoint Central21/10/202517/6/2026
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
AnalizadaBaja (3.3)0.26%—Zohocorp Manageengine Endpoint Central21/10/202517/6/2026
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
AnalizadaCrítica (9.3)2.8%⚠ Explotación activaMotex Lanscope Endpoint Manager20/10/202517/6/2026
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
AnalizadaMedia (4.9)0.36%—Cisco Telepresence Collaboration EndpointCisco Roomos15/10/202517/6/2026
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid…
AplazadaAlta (8.6)44%💥 ExploitFreepbx Endpoint ManagerAI14/10/202517/6/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. The fwbrand…
AplazadaAlta (8.6)38%💥 ExploitFreepbx Endpoint ManagerAI14/10/202517/6/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model,…
AplazadaAlta (8.6)0.53%—Freepbx Endpoint ManagerAI14/10/202517/6/2026
The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk…
AnalizadaMedia (4.7)0.21%—Microsoft Defender FOR Endpoint14/10/202530/9/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
AnalizadaMedia (5.5)0.62%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202530/9/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Orbitaley — Vulnerabilidades