Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.65%—Microsoft Defender FOR Endpoint8/10/202417/6/2026
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
AnalizadaAlta (7.2)16%—Ivanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
AnalizadaAlta (7.2)60%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
AnalizadaAlta (7.8)0.24%—Ivanti Endpoint Manager Mobile8/10/202417/6/2026
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
AnalizadaAlta (7.2)44%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/20241/10/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AplazadaMedia (6.8)0.51%—Freepbx OSS Endpoint ManagerAI1/10/202417/6/2026
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
AnalizadaCrítica (9.1)99%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Cloud Services Appliance19/9/202417/6/2026
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (8.2)59%—Ivanti Endpoint Manager12/9/202417/6/2026
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
ModificadaAlta (7.2)25%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)43%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)24%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)43%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)24%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)2.1%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaAlta (7.2)25%—Ivanti Endpoint Manager12/9/202417/6/2026
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaCrítica (9.8)53%💥 PoCIvanti Endpoint Manager12/9/202417/6/2026
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaMedia (6.7)0.36%—Ivanti Endpoint Manager10/9/202417/6/2026
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
AnalizadaAlta (8.8)1.1%—Ivanti Endpoint Manager10/9/202417/6/2026
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
AnalizadaAlta (8.6)1.8%—Ivanti Endpoint Manager10/9/202417/6/2026
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
AnalizadaMedia (5.3)1.2%—Ivanti Endpoint Manager10/9/202417/6/2026
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
AnalizadaCrítica (9.8)20%—Ivanti Endpoint Manager10/9/202417/6/2026
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaMedia (6)0.74%—Fortinet Forticlient Endpoint Management Server10/9/202417/6/2026
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited…
AnalizadaAlta (8.3)0.80%—Zohocorp Manageengine Endpoint Central30/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
Orbitaley — Vulnerabilidades