Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.63% | — | Zohocorp Manageengine Endpoint Central | 5/2/2025 | 17/6/2026 | ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat. | |
| Modificada | Alta (7.5) | 1.6% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/1/2025 | 17/6/2026 | A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read.… | |
| Analizada | Alta (7.8) | 0.51% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.8) | 18% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.5) | 2.7% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.44% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.4% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 2.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (7.8) | 9.2% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required. | |
| Analizada | Alta (7.2) | 64% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848. | |
| Analizada | Alta (7.5) | 90% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 91% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.2) | 3.5% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.5) | 3.6% | — | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Thousandeyes Endpoint Agent | 8/1/2025 | 17/6/2026 | A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certificates for hosted… | |
| Aplazada | Media (5.6) | 0.30% | 💥 PoC | Netskope Endpoint DLPAI | 19/12/2024 | 17/6/2026 | Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both independently… | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Defender FOR Endpoint | 12/12/2024 | 17/6/2026 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | |
| Aplazada | Media (6.1) | 0.39% | — | Ultimate Endpoints With Rest APIAI | 12/12/2024 | 17/6/2026 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Alta (8.1) | 1.7% | — | Microsoft Defender FOR Endpoint | 12/12/2024 | 17/6/2026 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+2 | 10/12/2024 | 17/6/2026 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | |
| Analizada | Media (4.3) | 0.27% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request… |