Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.51% | — | Mcafee Data Loss Prevention | 12/8/2020 | 17/6/2026 | Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section. | |
| Modificada | Media (6.3) | 0.60% | — | Mcafee Data Loss Prevention | 12/8/2020 | 17/6/2026 | Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages. | |
| Modificada | Alta (8.4) | 0.29% | — | Mcafee Total Protection | 5/8/2020 | 17/6/2026 | Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call. | |
| Analizada | Media (5.3) | 4.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+19 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 3.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+17 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Analizada | Baja (3.7) | 4.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+17 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Analizada | Baja (3.7) | 4.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+17 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Modificada | Media (4.3) | 0.86% | — | Mcafee WEB Gateway | 15/7/2020 | 17/6/2026 | Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL. | |
| Modificada | Alta (7.5) | 87% | 💥 PoC | Apache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+14 | 14/7/2020 | 25/8/2026 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. | |
| Modificada | Media (4.2) | 2.5% | — | OpenldapRedhat Enterprise LinuxOpensuse LeapMcafee Policy Auditor+1 | 14/7/2020 | 17/6/2026 | libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux. | |
| Modificada | Alta (7.8) | 0.37% | — | Mcafee Network Security Management | 3/7/2020 | 17/6/2026 | Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the root account via execution of carefully crafted commands from the restricted command line interface (CLI). | |
| Modificada | Alta (8.8) | 0.62% | 💥 PoC | Mcafee Total Protection | 3/7/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine. | |
| Modificada | Media (6.3) | 0.32% | — | Mcafee Total Protection | 3/7/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on… | |
| Modificada | Media (6.3) | 0.26% | — | Mcafee Total Protection | 3/7/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program… | |
| Modificada | Media (5.5) | 0.74% | — | Mcafee Advanced Threat Defense | 22/6/2020 | 17/6/2026 | Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefully crafted HTTP request parameter. | |
| Modificada | Media (5.5) | 0.54% | — | Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+690 | 15/6/2020 | 17/6/2026 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.40% | — | Mcafee Virusscan Enterprise | 10/6/2020 | 17/6/2026 | Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent. | |
| Modificada | Alta (7.8) | 0.42% | — | Mcafee Host Intrusion Prevention | 10/6/2020 | 17/6/2026 | DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary code via execution from a compromised folder. | |
| Modificada | Media (6.8) | 0.29% | — | Mcafee Virusscan Enterprise | 10/6/2020 | 17/6/2026 | Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked. | |
| Modificada | Alta (7.8) | 0.28% | — | Mcafee Virusscan Enterprise | 10/6/2020 | 17/6/2026 | Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges. | |
| Modificada | Alta (7.3) | 0.38% | — | Mcafee Agent | 10/6/2020 | 17/6/2026 | DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder. | |
| Modificada | Alta (8.2) | 0.32% | — | Mcafee Total Protection | 10/6/2020 | 17/6/2026 | Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files. | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Active Response | 8/5/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Active Response | 8/5/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. |