Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.28%—Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI8/9/202517/6/2026
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier…
AnalizadaAlta (7)0.23%—Ivanti Application ControlIvanti Security Controls14/1/202517/6/2026
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.
AnalizadaAlta (7.8)0.21%—Ivanti Application Control11/12/202417/6/2026
Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
AnalizadaCrítica (9.8)100%⚠ Explotación activaZohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+1818/1/202331/7/2026
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,…
ModificadaAlta (7.5)0.79%—Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware28/10/202217/6/2026
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
ModificadaCrítica (10)0.95%—Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware28/10/202217/6/2026
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
ModificadaCrítica (9.8)0.94%—Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware28/10/202217/6/2026
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
ModificadaMedia (4.3)2.2%—Zohocorp Manageengine Application Control Plus30/9/202017/6/2026
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently…
ModificadaMedia (4.3)1.8%—Zohocorp Manageengine Application Control Plus30/9/202017/6/2026
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.
ModificadaAlta (7.5)1.0%—Cisco ACE Application Control Engine Module A27/2/202016/6/2026
Cisco ACE A2(3.6) allows log retention DoS.
ModificadaAlta (8.8)65%—Trendmicro Endpoint Application Control23/5/201817/6/2026
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.
ModificadaMedia (5.9)15%—Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+105/3/201817/6/2026
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
ModificadaAlta (7.8)0.27%—Mcafee Application ControlMcafee Endpoint Security14/3/201717/6/2026
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local security protection via a command-line utility.
ModificadaAlta (7.8)0.41%—Mcafee Application Control14/3/201717/6/2026
Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code execution via an unauthorized use of IOCTL call.
ModificadaMedia (5.9)1.0%—Mcafee Application Control14/3/201717/6/2026
Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, and 6.1.3 before hotfix 357 and earlier allows attackers to create a malformed…
ModificadaMedia (5.5)0.36%—Mcafee Application ControlMcafee Change Control14/3/201717/6/2026
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.
ModificadaMedia (5.5)0.36%—Mcafee Application ControlMcafee Change Control14/3/201717/6/2026
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.
ModificadaAlta (7.5)1.9%—Cisco ACE Application Control Engine Module A1Cisco ACE Application Control Engine Module A3Cisco ACE Application Control Engine Module A4Cisco ACE Application Control Engine Module A5+512/9/201617/6/2026
Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb16317.
ModificadaAlta (8.8)2.8%—Cisco Application Control Engine Software26/2/201617/6/2026
The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801.
ModificadaMedia (6.6)2.3%—Microsoft WindowsMcafee Application Control12/1/201617/6/2026
The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges…
ModificadaMedia (4.3)1.8%—Cisco Application Control Engine 470027/8/201517/6/2026
The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCur23662.
ModificadaMedia (5)1.2%—Cisco Application Control Engine Module16/9/201216/6/2026
The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via application traffic, aka Bug ID CSCtw70879.
ModificadaMedia (5)0.99%—Mcafee Application ControlMcafee Change Control22/8/201216/6/2026
McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attributes of the password file, which allows local users to bypass authentication by executing a command.
ModificadaAlta (7.1)1.0%—Cisco Application Control Engine Software20/6/201216/6/2026
Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances, and read or…