Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaAlta (7.8)0.78%—Ivanti Endpoint Manager13/10/202517/6/2026
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202530/9/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaAlta (8.8)15%—Ivanti Endpoint Manager13/10/202530/9/2026
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (7.8)0.27%—Zohocorp Manageengine Endpoint Central25/9/202517/6/2026
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
AnalizadaAlta (8.8)21%—Ivanti Endpoint Manager9/9/202517/6/2026
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (8.8)14%—Ivanti Endpoint Manager9/9/202525/9/2026
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile8/7/202517/6/2026
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
AnalizadaAlta (7.2)1.1%—Ivanti Endpoint Manager8/7/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
AnalizadaAlta (8.4)0.22%—Ivanti Endpoint Manager8/7/202517/6/2026
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
AnalizadaAlta (8.4)0.22%—Ivanti Endpoint Manager8/7/202517/6/2026
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
AnalizadaAlta (7.2)17%—Ivanti Endpoint Manager Mobile8/7/202517/6/2026
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
AplazadaCrítica (10)7.1%—Sangfor Endpoint Detection AND ResponseAI24/6/202517/6/2026
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to…
AnalizadaAlta (7.5)0.82%—ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud18/6/202517/6/2026
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a…
AnalizadaAlta (7.8)0.13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
AnalizadaCrítica (9.8)1.1%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
AnalizadaCrítica (9.8)0.55%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
AnalizadaAlta (8.8)0.33%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaAlta (8.8)0.84%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaCrítica (9.8)13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
Orbitaley — Vulnerabilidades