Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.63%—Zohocorp Manageengine Endpoint Central5/2/202517/6/2026
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
ModificadaAlta (7.5)1.6%—ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud22/1/202517/6/2026
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read.…
AnalizadaAlta (7.8)0.51%—Ivanti Endpoint Manager14/1/202517/6/2026
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.8)18%—Ivanti Endpoint Manager14/1/202517/6/2026
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.5)2.7%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.8)0.44%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.4%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)2.6%—Ivanti Endpoint Manager14/1/202517/6/2026
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.8)0.38%—Ivanti Endpoint Manager14/1/202517/6/2026
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (7.8)9.2%—Ivanti Endpoint Manager14/1/202517/6/2026
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
AnalizadaAlta (7.2)64%—Ivanti Endpoint Manager14/1/202517/6/2026
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
AnalizadaAlta (7.5)90%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)91%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.2)3.5%—Ivanti Endpoint Manager14/1/202517/6/2026
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.5)3.6%—Ivanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaMedia (4.8)0.17%—Cisco Thousandeyes Endpoint Agent8/1/202517/6/2026
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certificates for hosted…
AplazadaMedia (5.6)0.30%💥 PoCNetskope Endpoint DLPAI19/12/202417/6/2026
Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both independently…
AnalizadaMedia (6.5)1.1%—Microsoft Defender FOR Endpoint12/12/202417/6/2026
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.
AplazadaMedia (6.1)0.39%—Ultimate Endpoints With Rest APIAI12/12/202417/6/2026
The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AnalizadaAlta (8.1)1.7%—Microsoft Defender FOR Endpoint12/12/202417/6/2026
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
AnalizadaMedia (4.3)0.27%—Cisco Telepresence Collaboration EndpointCisco Roomos15/11/202417/6/2026
A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request…
Orbitaley — Vulnerabilidades