Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.82% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 1.7% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 0.82% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 0.83% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 0.83% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Media (6.5) | 0.83% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Alta (7.8) | 0.78% | — | Ivanti Endpoint Manager | 13/10/2025 | 17/6/2026 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Media (6.5) | 0.82% | — | Ivanti Endpoint Manager | 13/10/2025 | 30/9/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Modificada | Alta (8.8) | 15% | — | Ivanti Endpoint Manager | 13/10/2025 | 30/9/2026 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | |
| Analizada | Alta (7.8) | 0.27% | — | Zohocorp Manageengine Endpoint Central | 25/9/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. | |
| Analizada | Alta (8.8) | 21% | — | Ivanti Endpoint Manager | 9/9/2025 | 17/6/2026 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | |
| Analizada | Alta (8.8) | 14% | — | Ivanti Endpoint Manager | 9/9/2025 | 25/9/2026 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 8/7/2025 | 17/6/2026 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution | |
| Analizada | Alta (7.2) | 1.1% | — | Ivanti Endpoint Manager | 8/7/2025 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database | |
| Analizada | Alta (8.4) | 0.22% | — | Ivanti Endpoint Manager | 8/7/2025 | 17/6/2026 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords. | |
| Analizada | Alta (8.4) | 0.22% | — | Ivanti Endpoint Manager | 8/7/2025 | 17/6/2026 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords. | |
| Analizada | Alta (7.2) | 17% | — | Ivanti Endpoint Manager Mobile | 8/7/2025 | 17/6/2026 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution | |
| Aplazada | Crítica (10) | 7.1% | — | Sangfor Endpoint Detection AND ResponseAI | 24/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to… | |
| Analizada | Alta (7.5) | 0.82% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 18/6/2025 | 17/6/2026 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a… | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method. | |
| Analizada | Crítica (9.8) | 0.55% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | |
| Analizada | Alta (8.8) | 0.33% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.84% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method. |