Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 3.5% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.5) | 3.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+2 | 10/12/2024 | 17/6/2026 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | |
| Analizada | Alta (7.2) | 3.2% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 18% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 68% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.2% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.4% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.4% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 40% | 💥 PoC | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Alta (8.8) | 1.7% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 1.8% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.1% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 26% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 19% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.67% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.8) | 6.0% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 16% | — | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. | |
| Analizada | Alta (7.2) | 60% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. | |
| Analizada | Alta (7.8) | 0.24% | — | Ivanti Endpoint Manager Mobile | 8/10/2024 | 17/6/2026 | Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. | |
| Analizada | Alta (7.2) | 44% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 1/10/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. |