Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.51% | — | Freepbx OSS Endpoint ManagerAI | 1/10/2024 | 17/6/2026 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4. | |
| Analizada | Crítica (9.1) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Cloud Services Appliance | 19/9/2024 | 17/6/2026 | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | |
| Analizada | Alta (8.2) | 59% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | |
| Modificada | Alta (7.2) | 25% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 43% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 24% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 43% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 24% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 25% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Crítica (9.8) | 53% | 💥 PoC | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Media (6.7) | 0.36% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM. | |
| Analizada | Alta (8.8) | 1.1% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality. | |
| Analizada | Alta (8.6) | 1.8% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network. | |
| Analizada | Media (5.3) | 1.2% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices. | |
| Analizada | Crítica (9.8) | 20% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources. | |
| Modificada | Alta (8.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | |
| Analizada | Media (6.5) | 0.94% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information | |
| Analizada | Alta (8) | 3.1% | — | Ivanti Endpoint Manager | 29/7/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8) | 8.5% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | |
| Modificada | Alta (8) | 8.5% | — | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. |