Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)1.7%—Eset Endpoint AntivirusEset Endpoint Security2/3/201717/6/2026
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation…
ModificadaMedia (5.1)1.1%💥 ExploitMcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+38/4/201617/6/2026
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before…
ModificadaMedia (6.9)1.3%—Eset Smart SecurityEset Endpoint Security23/9/201417/6/2026
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call.
ModificadaMedia (4.3)0.60%—Checkpoint Endpoint Security MI Server R7322/1/201417/6/2026
Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.
ModificadaBaja (3.3)0.20%—Checkpoint Endpoint Security30/11/201316/6/2026
Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few…
ModificadaBaja (3.3)0.21%—Checkpoint Endpoint Security30/11/201316/6/2026
Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are…
ModificadaMedia (6.2)0.43%—Sophos Endpoint Security AND Control25/8/201216/6/2026
Race condition in Sophos Endpoint Security and Control 9.0.5 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.9)0.40%—Checkpoint Endpoint ConnectCheckpoint Endpoint SecurityCheckpoint Endpoint Security VPNCheckpoint Remote Access Clients19/6/201216/6/2026
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the…
ModificadaAlta (10)2.3%—IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Proventia Network Mail Security System Vitual ApplianceIBM Proventia Network Multi-function Security20/7/200916/6/2026
Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass…
ModificadaAlta (10)2.7%—IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Network Multi-function SecurityIBM Proventia Network Mail Security System Virtual Appliance3/4/200916/6/2026
Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of…
ModificadaAlta (7.2)0.37%—Novell Zenworks Endpoint Security Management9/1/200816/6/2026
STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the…
ModificadaMedia (5)18%💥 ExploitSophos Anti-virusSophos Endpoint Security1/11/200616/6/2026
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and…
ModificadaMedia (6.4)21%💥 ExploitSophos Anti-virusSophos Endpoint Security1/11/200616/6/2026
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name…
ModificadaMedia (5)18%💥 ExploitSophos Anti-virusSophos Endpoint Security1/11/200616/6/2026
Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that…
Orbitaley — Vulnerabilidades