Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.25% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links whilst an anti-virus scan was in progress. This… | |
| Modificada | Media (6.5) | 0.64% | — | Mcafee Endpoint Security | 15/4/2020 | 17/6/2026 | Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled… | |
| Modificada | Media (6.7) | 0.17% | — | Mcafee Endpoint Security | 1/4/2020 | 17/6/2026 | Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import. | |
| Modificada | Alta (7.8) | 0.41% | — | Mcafee Application AND Change Control | 26/3/2020 | 17/6/2026 | DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder. | |
| Modificada | Media (4.8) | 0.52% | — | Mcafee Network Security Manager | 18/3/2020 | 17/6/2026 | Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors. | |
| Modificada | Media (4.8) | 0.52% | — | Mcafee Network Security Manager | 18/3/2020 | 17/6/2026 | Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.30% | — | Mcafee Advanced Threat Defense | 12/3/2020 | 17/6/2026 | Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command. | |
| Modificada | Media (4.4) | 0.24% | — | Mcafee Agent | 12/3/2020 | 17/6/2026 | Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility. | |
| Modificada | Media (6.1) | 1.2% | — | Mcafee WEB Advisor | 24/2/2020 | 17/6/2026 | Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack. | |
| Modificada | Media (5.5) | 0.50% | — | Mcafee Data Exchange Layer | 17/2/2020 | 17/6/2026 | Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files. | |
| Modificada | Media (5.5) | 0.21% | — | Mcafee Endpoint Security | 14/2/2020 | 17/6/2026 | Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS. | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of… | |
| Modificada | Alta (8.1) | 4.9% | — | Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+23 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (4.8) | 3.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.2% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Alta (7.8) | 0.34% | — | Mcafee Techcheck | 11/12/2019 | 17/6/2026 | DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker. | |
| Modificada | Media (6.5) | 1.5% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site. | |
| Modificada | Media (6.5) | 0.94% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site. | |
| Modificada | Alta (8.6) | 0.66% | — | Mcafee Client Proxy | 22/11/2019 | 17/6/2026 | Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network… | |
| Modificada | Alta (7.8) | 0.91% | 💥 PoC | Mcafee Advanced Threat Defense | 14/11/2019 | 17/6/2026 | Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated… | |
| Modificada | Media (6.5) | 1.4% | — | Mcafee Advanced Threat Defense | 14/11/2019 | 17/6/2026 | Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests. | |
| Modificada | Alta (8.8) | 1.1% | — | Mcafee Advanced Threat Defense | 14/11/2019 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads. | |
| Modificada | Media (6.5) | 0.53% | — | Mcafee Data Loss Prevention | 14/11/2019 | 17/6/2026 | Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity. | |
| Modificada | Alta (8.8) | 1.2% | — | Mcafee Advanced Threat Defense | 13/11/2019 | 17/6/2026 | Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests. |