Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.65% | — | Microsoft Defender FOR Endpoint | 8/10/2024 | 17/6/2026 | Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.2) | 16% | — | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. | |
| Analizada | Alta (7.2) | 60% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. | |
| Analizada | Alta (7.8) | 0.24% | — | Ivanti Endpoint Manager Mobile | 8/10/2024 | 17/6/2026 | Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. | |
| Analizada | Alta (7.2) | 44% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 1/10/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| Aplazada | Media (6.8) | 0.51% | — | Freepbx OSS Endpoint ManagerAI | 1/10/2024 | 17/6/2026 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4. | |
| Analizada | Crítica (9.1) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Cloud Services Appliance | 19/9/2024 | 17/6/2026 | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | |
| Analizada | Alta (8.2) | 59% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | |
| Modificada | Alta (7.2) | 25% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 43% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 24% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 43% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 24% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Alta (7.2) | 25% | — | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Modificada | Crítica (9.8) | 53% | 💥 PoC | Ivanti Endpoint Manager | 12/9/2024 | 17/6/2026 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Media (6.7) | 0.36% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM. | |
| Analizada | Alta (8.8) | 1.1% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality. | |
| Analizada | Alta (8.6) | 1.8% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network. | |
| Analizada | Media (5.3) | 1.2% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices. | |
| Analizada | Crítica (9.8) | 20% | — | Ivanti Endpoint Manager | 10/9/2024 | 17/6/2026 | SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Media (6) | 0.74% | — | Fortinet Forticlient Endpoint Management Server | 10/9/2024 | 17/6/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited… | |
| Analizada | Alta (8.3) | 0.80% | — | Zohocorp Manageengine Endpoint Central | 30/8/2024 | 17/6/2026 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15 |