Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)3.5%—Ivanti Endpoint Manager14/1/202517/6/2026
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.5)3.6%—Ivanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
AnalizadaAlta (7.2)3.2%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.8)18%—Ivanti Endpoint Manager13/11/202417/6/2026
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
AnalizadaAlta (7.2)1.7%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.7%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)68%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.7%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)3.2%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.7%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)3.4%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)3.4%—Ivanti Endpoint Manager13/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.8)40%💥 PoCIvanti Endpoint Manager12/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaAlta (8.8)1.7%—Ivanti Endpoint Manager12/11/202417/6/2026
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (7.2)1.8%—Ivanti Endpoint Manager12/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.1%—Ivanti Endpoint Manager12/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)26%—Ivanti Endpoint Manager12/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)19%—Ivanti Endpoint Manager12/11/202417/6/2026
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.8)0.67%—Ivanti Endpoint Manager12/11/202417/6/2026
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
AnalizadaAlta (7.8)6.0%—Ivanti Endpoint Manager12/11/202417/6/2026
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
AnalizadaAlta (7.2)16%—Ivanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
AnalizadaAlta (7.2)60%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
AnalizadaAlta (7.8)0.24%—Ivanti Endpoint Manager Mobile8/10/202417/6/2026
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
AnalizadaAlta (7.2)44%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/20241/10/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Orbitaley — Vulnerabilidades