Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.19% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this… | |
| Analizada | Media (6.7) | 0.21% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A… | |
| Analizada | Media (4.4) | 0.19% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco Telepresence Collaboration Endpoint | 15/11/2024 | 17/6/2026 | A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability is due to insufficient version control. An attacker could exploit this… | |
| Analizada | Media (6.8) | 0.43% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/11/2024 | 17/6/2026 | A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to insufficient identity verification. An attacker… | |
| Analizada | Alta (7) | 0.17% | — | Intel Endpoint Management Assistant | 13/11/2024 | 17/6/2026 | Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 3.2% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 18% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 68% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.2% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.4% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 3.4% | — | Ivanti Endpoint Manager | 13/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 40% | 💥 PoC | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Alta (8.8) | 1.7% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | |
| Analizada | Alta (7.2) | 1.8% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.1% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 26% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 19% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.67% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.8) | 6.0% | — | Ivanti Endpoint Manager | 12/11/2024 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required. | |
| Analizada | Alta (7.8) | 0.45% | — | Zohocorp Manageengine Endpoint Central | 7/11/2024 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines. |