Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.7% | — | Eset Endpoint AntivirusEset Endpoint Security | 2/3/2017 | 17/6/2026 | The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation… | |
| Modificada | Media (5.1) | 1.1% | 💥 Exploit | Mcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+3 | 8/4/2016 | 17/6/2026 | The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before… | |
| Modificada | Media (6.9) | 1.3% | — | Eset Smart SecurityEset Endpoint Security | 23/9/2014 | 17/6/2026 | The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call. | |
| Modificada | Media (4.3) | 0.60% | — | Checkpoint Endpoint Security MI Server R73 | 22/1/2014 | 17/6/2026 | Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client. | |
| Modificada | Baja (3.3) | 0.20% | — | Checkpoint Endpoint Security | 30/11/2013 | 16/6/2026 | Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few… | |
| Modificada | Baja (3.3) | 0.21% | — | Checkpoint Endpoint Security | 30/11/2013 | 16/6/2026 | Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are… | |
| Modificada | Media (6.2) | 0.43% | — | Sophos Endpoint Security AND Control | 25/8/2012 | 16/6/2026 | Race condition in Sophos Endpoint Security and Control 9.0.5 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Media (6.9) | 0.40% | — | Checkpoint Endpoint ConnectCheckpoint Endpoint SecurityCheckpoint Endpoint Security VPNCheckpoint Remote Access Clients | 19/6/2012 | 16/6/2026 | Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the… | |
| Modificada | Alta (10) | 2.3% | — | IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Proventia Network Mail Security System Vitual ApplianceIBM Proventia Network Multi-function Security | 20/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass… | |
| Modificada | Alta (10) | 2.7% | — | IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Network Multi-function SecurityIBM Proventia Network Mail Security System Virtual Appliance | 3/4/2009 | 16/6/2026 | Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of… | |
| Modificada | Alta (7.2) | 0.37% | — | Novell Zenworks Endpoint Security Management | 9/1/2008 | 16/6/2026 | STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the… | |
| Modificada | Media (5) | 18% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and… | |
| Modificada | Media (6.4) | 21% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name… | |
| Modificada | Media (5) | 18% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that… |