Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.8) | 0.28% | — | Cisco Advanced Malware Protection FOR EndpointsCisco ClamavCisco Immunet | 8/4/2021 | 17/6/2026 | A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected Windows system. To exploit this vulnerability,… | |
| Modificada | Alta (7) | 0.36% | — | Cisco Advanced Malware ProtectionMadshi MadcodehookMorphisec Unified Threat Prevention Platform | 30/1/2021 | 17/6/2026 | A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions. | |
| Modificada | Alta (7.3) | 0.44% | — | Cisco Advanced Malware Protection FOR EndpointsCisco Immunet | 20/1/2021 | 17/6/2026 | A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need valid credentials on the Windows… | |
| Modificada | Media (6.3) | 0.26% | — | Cisco Advanced Malware Protection FOR EndpointsCisco Clam AntivirusFedoraproject FedoraDebian Linux+1 | 18/6/2020 | 17/6/2026 | A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local… | |
| Modificada | Media (5.5) | 0.33% | — | Cisco Advanced Malware Protection FOR Endpoints | 22/5/2020 | 17/6/2026 | A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.5) | 0.33% | — | Cisco Advanced Malware Protection FOR Endpoints | 22/5/2020 | 17/6/2026 | A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability… | |
| Modificada | Media (6.1) | 0.56% | — | Cisco Advanced Malware Protection FOR Endpoints | 22/5/2020 | 17/6/2026 | A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP for Endpoints service. The vulnerability is due to… | |
| Modificada | Media (6.7) | 0.27% | — | Cisco Advanced Malware Protection FOR Endpoints | 6/7/2019 | 17/6/2026 | A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.7) | 0.33% | — | Cisco Advanced Malware Protection FOR Endpoints | 13/11/2018 | 17/6/2026 | A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could allow an authenticated, local attacker to disable system scanning services or take other actions to prevent detection of unauthorized intrusions. To exploit this vulnerability, the attacker would need… | |
| Modificada | Media (5.5) | 0.97% | 💥 Exploit | Cisco Advanced Malware Protection FOR EndpointsCisco Immunet FOR Endpoints | 8/11/2018 | 17/6/2026 | A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being… | |
| Modificada | Media (5.9) | 1.5% | — | Cisco Advanced Malware Protection FOR Endpoints | 1/8/2018 | 17/6/2026 | A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The vulnerability exists if the affected software is running in Block network… | |
| Modificada | Media (5.8) | 1.2% | — | Cisco Advanced Malware Protection FOR Endpoints | 19/4/2018 | 17/6/2026 | A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An… | |
| Modificada | Media (6.7) | 0.54% | — | Cisco Advanced Malware Protection FOR Endpoints | 16/11/2017 | 17/6/2026 | An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory where a crafted DLL has… | |
| Modificada | Media (6.7) | 0.30% | — | Cisco Advanced Malware Protection | 22/10/2017 | 17/6/2026 | The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this… |