Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.51%—Freepbx OSS Endpoint ManagerAI1/10/202417/6/2026
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
AnalizadaCrítica (9.1)99%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Cloud Services Appliance19/9/202417/6/2026
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (8.2)59%—Ivanti Endpoint Manager12/9/202417/6/2026
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
ModificadaAlta (7.2)25%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)43%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)24%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)43%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)24%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)25%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaCrítica (9.8)53%💥 PoCIvanti Endpoint Manager12/9/202417/6/2026
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaMedia (6.7)0.36%—Ivanti Endpoint Manager10/9/202417/6/2026
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
AnalizadaAlta (8.8)1.1%—Ivanti Endpoint Manager10/9/202417/6/2026
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
AnalizadaAlta (8.6)1.8%—Ivanti Endpoint Manager10/9/202417/6/2026
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
AnalizadaMedia (5.3)1.2%—Ivanti Endpoint Manager10/9/202417/6/2026
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
AnalizadaCrítica (9.8)20%—Ivanti Endpoint Manager10/9/202417/6/2026
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
ModificadaAlta (7.5)1.2%—Ivanti Endpoint Manager Mobile7/8/202417/6/2026
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
ModificadaAlta (8.8)2.3%—Ivanti Endpoint Manager Mobile7/8/202417/6/2026
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
ModificadaCrítica (9.8)2.3%—Ivanti Endpoint Manager Mobile7/8/202417/6/2026
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
AnalizadaMedia (6.5)0.94%—Ivanti Endpoint Manager Mobile7/8/202417/6/2026
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information
AnalizadaAlta (8)3.1%—Ivanti Endpoint Manager29/7/202417/6/2026
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.
ModificadaAlta (8)8.5%—Ivanti Endpoint Manager31/5/202417/6/2026
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
ModificadaAlta (8)8.5%—Ivanti Endpoint Manager31/5/202417/6/2026
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.