Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

307 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.61%—Helix ALMAI28/6/202417/6/2026
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
AplazadaCrítica (9.8)0.93%—Trellix IPS ManagerAI14/6/202417/6/2026
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
ModificadaMedia (5.4)0.31%—Trellix Xconsole13/6/202417/6/2026
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end…
AplazadaMedia (6.5)0.25%—Felixmoira Popup More PopupsAI17/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1.
AplazadaCrítica (9.3)0.94%—Netflix ConsolemeAI16/5/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.
AplazadaAlta (7.5)0.23%—Trellix Epolicy OrchestratorAI16/5/202417/6/2026
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was possible through using…
AnalizadaCrítica (9.8)0.55%—Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch19/3/202417/6/2026
A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. It has been classified as critical. This affects an unknown part of the file /api/client/editemedia.php. The manipulation of the argument number/enterprise_uuid leads to sql injection. It is possible to initiate the…
AnalizadaCrítica (9.8)1.9%💥 ExploitKelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch19/3/202417/6/2026
A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php. The manipulation of the argument uuid leads to sql injection. The attack may be launched…
AnalizadaCrítica (9.8)0.56%—Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch19/3/202417/6/2026
A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this vulnerability is an unknown functionality of the file api/client/down_file.php. The manipulation of the argument uuid leads to sql injection. The attack can be…
AnalizadaCrítica (9.8)0.62%—Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch17/3/202417/6/2026
A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240313. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file api/client/get_extension_yl.php. The manipulation of the argument imei leads to sql injection. The attack can…
AnalizadaMedia (5.4)0.62%—Felixschwarz Mjml-python22/2/202417/6/2026
The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users of `FelixSchwarz/mjml-python` who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like…
ModificadaMedia (5.4)0.34%—Trellix Central Management System13/2/202417/6/2026
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
AnalizadaAlta (7.2)0.66%—Felixmoira AI Popup2/2/202417/6/2026
The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files ending…
ModificadaAlta (7.8)0.75%—Perforce Helix Sync1/2/202417/6/2026
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
ModificadaAlta (7.2)1.2%—Schlix CMS31/1/202417/6/2026
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.
ModificadaMedia (6.1)0.42%—Trellix Endpoint Security WEB Control10/1/202417/6/2026
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
ModificadaAlta (7.8)0.17%—Trellix Agent9/1/202417/6/2026
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO,…
ModificadaAlta (7.8)0.18%—Trellix Anti-malware Engine9/1/202417/6/2026
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that…
ModificadaAlta (7.5)0.44%—Wallix BastionWallix Bastion Access Manager8/1/202417/6/2026
WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.
ModificadaAlta (7.2)0.85%—Trellix Enterprise Security Manager30/11/202317/6/2026
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.
ModificadaMedia (4.3)0.24%—Trellix Enterprise Security Manager29/11/202317/6/2026
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid…
ModificadaAlta (7.2)0.94%—Trellix Application AND Change Control27/11/202317/6/2026
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could lead to an authorised administrator attacker executing arbitrary code through uploading a specially crafted GTI reputation file. The…
ModificadaAlta (7.8)0.21%—Trellix Getsusp16/11/202317/6/2026
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused by GetSusp not correctly protecting a directory that it creates during execution, allowing an attacker…
ModificadaAlta (7.5)0.95%—Perforce Helix Core8/11/202317/6/2026
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.
ModificadaCrítica (9.8)1.1%—Perforce Helix Core8/11/202317/6/2026
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
Orbitaley — Vulnerabilidades