Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Mcafee Epolicy Orchestrator | 1/5/2013 | 16/6/2026 | Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory. | |
| Modificada | Alta (7.9) | 2.5% | 💥 Exploit | Mcafee Epolicy Orchestrator | 1/5/2013 | 16/6/2026 | SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel. | |
| Modificada | Media (4) | 0.97% | — | Mcafee Epolicy Orchestrator | 22/8/2012 | 16/6/2026 | McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL. | |
| Modificada | Media (5.4) | 6.2% | 💥 Exploit | Mcafee AgentMcafee CMAMcafee Epolicy OrchestratorMcafee Framework | 17/3/2008 | 16/6/2026 | Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender… | |
| Modificada | Alta (7.6) | 5.0% | — | Mcafee Common Management AgentMcafee Epolicy OrchestratorMcafee Protectionpilot | 12/7/2007 | 16/6/2026 | Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 7.7% | — | Mcafee Epolicy OrchestratorMcafee Protectionpilot | 16/3/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1)… | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Mcafee Epolicy OrchestratorMcafee Protectionpilot | 5/10/2006 | 16/6/2026 | Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header. | |
| Modificada | Media (5) | 1.9% | — | Mcafee Epolicy Orchestrator Agent | 18/7/2006 | 16/6/2026 | Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename in a PropsResponse (PackageType) request. | |
| Modificada | Baja (2.1) | 0.48% | — | Network Associates Epolicy Orchestrator Agent | 12/8/2005 | 16/6/2026 | The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory. | |
| Modificada | Alta (7.5) | 3.2% | — | Mcafee Epolicy Orchestrator | 14/6/2004 | 16/6/2026 | McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81. | |
| Modificada | Media (5) | 37% | 💥 Exploit | Mcafee Epolicy Orchestrator | 17/2/2004 | 16/6/2026 | McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 2.4% | — | Mcafee Epolicy Orchestrator | 27/8/2003 | 16/6/2026 | Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request. | |
| Modificada | Alta (7.5) | 3.7% | — | Mcafee Epolicy Orchestrator | 27/8/2003 | 16/6/2026 | Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters. | |
| Modificada | Alta (7.2) | 0.56% | — | Mcafee Epolicy Orchestrator | 27/8/2003 | 16/6/2026 | The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to… | |
| Modificada | Alta (7.5) | 3.0% | — | Mcafee Epolicy Orchestrator | 27/8/2003 | 16/6/2026 | Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution. | |
| Modificada | Alta (10) | 8.4% | — | Mcafee Epolicy Orchestrator | 11/4/2003 | 16/6/2026 | Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings. |