Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

613 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)0.25%—Mcafee Endpoint Security15/4/202017/6/2026
Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links whilst an anti-virus scan was in progress. This…
ModificadaMedia (6.5)0.64%—Mcafee Endpoint Security15/4/202017/6/2026
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled…
ModificadaMedia (6.7)0.17%—Mcafee Endpoint Security1/4/202017/6/2026
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
ModificadaAlta (7.8)0.41%—Mcafee Application AND Change Control26/3/202017/6/2026
DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.
ModificadaMedia (4.8)0.52%—Mcafee Network Security Manager18/3/202017/6/2026
Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
ModificadaMedia (4.8)0.52%—Mcafee Network Security Manager18/3/202017/6/2026
Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
ModificadaAlta (7.8)0.30%—Mcafee Advanced Threat Defense12/3/202017/6/2026
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.
ModificadaMedia (4.4)0.24%—Mcafee Agent12/3/202017/6/2026
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.
ModificadaMedia (6.1)1.2%—Mcafee WEB Advisor24/2/202017/6/2026
Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack.
ModificadaMedia (5.5)0.50%—Mcafee Data Exchange Layer17/2/202017/6/2026
Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
ModificadaMedia (5.5)0.21%—Mcafee Endpoint Security14/2/202017/6/2026
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.
ModificadaBaja (3.7)4.0%—Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1915/1/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of…
ModificadaAlta (8.1)4.9%—Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+2315/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols…
ModificadaMedia (4.8)3.0%—Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2015/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaBaja (3.7)3.2%—Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2015/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise…
ModificadaBaja (3.7)4.0%—Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2015/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols…
ModificadaAlta (7.8)0.34%—Mcafee Techcheck11/12/201917/6/2026
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.
ModificadaMedia (6.5)1.5%—Mcafee Webadvisor3/12/201917/6/2026
API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site.
ModificadaMedia (6.5)0.94%—Mcafee Webadvisor3/12/201917/6/2026
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site.
ModificadaAlta (8.6)0.66%—Mcafee Client Proxy22/11/201917/6/2026
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network…
ModificadaAlta (7.8)0.91%💥 PoCMcafee Advanced Threat Defense14/11/201917/6/2026
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated…
ModificadaMedia (6.5)1.4%—Mcafee Advanced Threat Defense14/11/201917/6/2026
Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.
ModificadaAlta (8.8)1.1%—Mcafee Advanced Threat Defense14/11/201917/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.
ModificadaMedia (6.5)0.53%—Mcafee Data Loss Prevention14/11/201917/6/2026
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
ModificadaAlta (8.8)1.2%—Mcafee Advanced Threat Defense13/11/201917/6/2026
Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.
Orbitaley — Vulnerabilidades