Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.25%—Mcafee Endpoint Security15/4/202017/6/2026
Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file
ModificadaMedia (6.3)0.25%—Mcafee Endpoint Security15/4/202017/6/2026
Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links whilst an anti-virus scan was in progress. This…
ModificadaMedia (6.5)0.64%—Mcafee Endpoint Security15/4/202017/6/2026
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled…
ModificadaMedia (6.7)0.17%—Mcafee Endpoint Security1/4/202017/6/2026
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
ModificadaMedia (5.5)0.21%—Mcafee Endpoint Security14/2/202017/6/2026
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.
ModificadaAlta (7.8)0.65%—Bitdefender Endpoint Security Tools27/1/202017/6/2026
An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecurityService.exe versions prior to 6.6.11.163.
ModificadaAlta (7.5)1.2%—Checkpoint Endpoint Security Clients23/12/201917/6/2026
A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.
ModificadaAlta (7.8)0.30%—Eset Cyber SecurityEset Endpoint AntivirusEset Endpoint Security14/10/201917/6/2026
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.
ModificadaMedia (5.5)0.23%—Mcafee Endpoint Security9/10/201917/6/2026
Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.
ModificadaMedia (5.3)0.33%—Mcafee Endpoint Security9/10/201917/6/2026
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.
ModificadaAlta (7.3)0.29%—Dell EncryptionDell Endpoint Security Suite Enterprise7/10/201917/6/2026
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially…
ModificadaAlta (7.8)1.1%—Checkpoint Capsule Docs Standalone ClientCheckpoint Endpoint SecurityCheckpoint Remote Access Clients29/8/201917/6/2026
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the…
ModificadaMedia (6.7)0.57%—Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security30/7/201917/6/2026
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with…
ModificadaCrítica (9.8)1.2%—Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+220/6/201917/6/2026
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
ModificadaMedia (4.4)0.97%—Checkpoint Endpoint Security ClientsCheckpoint Remote Access ClientsCheckpoint Capsule Docs20/6/201917/6/2026
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary,…
ModificadaAlta (7.5)0.76%—Mcafee Endpoint Security15/5/201917/6/2026
Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious sites where the GTI reputation is…
ModificadaAlta (7)0.33%—Checkpoint Endpoint Security29/4/201917/6/2026
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.
ModificadaAlta (7.8)1.0%💥 ExploitCheckpoint Endpoint SecurityCheckpoint Zonealarm22/4/201917/6/2026
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker…
ModificadaAlta (7.8)0.38%—Mcafee Endpoint Security28/2/201917/6/2026
Privilege Escalation vulnerability in Microsoft Windows client in McAfee Endpoint Security (ENS) 10.6.1 and earlier allows local users to gain elevated privileges via a specific set of circumstances.
ModificadaAlta (7.5)0.55%—Dell EncryptionDell Endpoint Security Suite Enterprise11/10/201817/6/2026
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially…
ModificadaMedia (5.3)0.18%—Mcafee Endpoint Security FOR Linux Threat PreventionMcafee Endpoint Security Linux Threat Prevention18/9/201817/6/2026
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete…
ModificadaMedia (4.4)0.53%—Mcafee Anti-virus PlusMcafee Endpoint SecurityMcafee Host Intrusion PreventionMcafee Internet Security+23/4/201817/6/2026
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
ModificadaAlta (7.5)1.9%—Ivanti Endpoint Security15/2/201817/6/2026
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.
ModificadaMedia (6.1)0.55%—Intel Security Mcafee Endpoint Security WEB Control14/3/201717/6/2026
Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.
ModificadaAlta (7.8)0.27%—Mcafee Application ControlMcafee Endpoint Security14/3/201717/6/2026
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local security protection via a command-line utility.
Orbitaley — Vulnerabilidades