Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.28% | — | Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI | 8/9/2025 | 17/6/2026 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier… | |
| Analizada | Alta (7) | 0.23% | — | Ivanti Application ControlIvanti Security Controls | 14/1/2025 | 17/6/2026 | A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality. | |
| Analizada | Alta (7.8) | 0.21% | — | Ivanti Application Control | 11/12/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Alta (7.5) | 0.79% | — | Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware | 28/10/2022 | 17/6/2026 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories. | |
| Modificada | Crítica (10) | 0.95% | — | Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware | 28/10/2022 | 17/6/2026 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | |
| Modificada | Crítica (9.8) | 0.94% | — | Honeywell C200 FirmwareHoneywell C200e FirmwareHoneywell C300 FirmwareHoneywell Application Control Environment Firmware | 28/10/2022 | 17/6/2026 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | |
| Modificada | Media (4.3) | 2.2% | — | Zohocorp Manageengine Application Control Plus | 30/9/2020 | 17/6/2026 | An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently… | |
| Modificada | Media (4.3) | 1.8% | — | Zohocorp Manageengine Application Control Plus | 30/9/2020 | 17/6/2026 | An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed. | |
| Modificada | Alta (7.5) | 1.0% | — | Cisco ACE Application Control Engine Module A2 | 7/2/2020 | 16/6/2026 | Cisco ACE A2(3.6) allows log retention DoS. | |
| Modificada | Alta (8.8) | 65% | — | Trendmicro Endpoint Application Control | 23/5/2018 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability. | |
| Modificada | Media (5.9) | 15% | — | Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+10 | 5/3/2018 | 17/6/2026 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Alta (7.8) | 0.27% | — | Mcafee Application ControlMcafee Endpoint Security | 14/3/2017 | 17/6/2026 | Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local security protection via a command-line utility. | |
| Modificada | Alta (7.8) | 0.41% | — | Mcafee Application Control | 14/3/2017 | 17/6/2026 | Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code execution via an unauthorized use of IOCTL call. | |
| Modificada | Media (5.9) | 1.0% | — | Mcafee Application Control | 14/3/2017 | 17/6/2026 | Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, and 6.1.3 before hotfix 357 and earlier allows attackers to create a malformed… | |
| Modificada | Media (5.5) | 0.36% | — | Mcafee Application ControlMcafee Change Control | 14/3/2017 | 17/6/2026 | A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions. | |
| Modificada | Media (5.5) | 0.36% | — | Mcafee Application ControlMcafee Change Control | 14/3/2017 | 17/6/2026 | A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions. | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco ACE Application Control Engine Module A1Cisco ACE Application Control Engine Module A3Cisco ACE Application Control Engine Module A4Cisco ACE Application Control Engine Module A5+5 | 12/9/2016 | 17/6/2026 | Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb16317. | |
| Modificada | Alta (8.8) | 2.8% | — | Cisco Application Control Engine Software | 26/2/2016 | 17/6/2026 | The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801. | |
| Modificada | Media (6.6) | 2.3% | — | Microsoft WindowsMcafee Application Control | 12/1/2016 | 17/6/2026 | The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges… | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Application Control Engine 4700 | 27/8/2015 | 17/6/2026 | The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCur23662. | |
| Modificada | Media (5) | 1.2% | — | Cisco Application Control Engine Module | 16/9/2012 | 16/6/2026 | The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via application traffic, aka Bug ID CSCtw70879. | |
| Modificada | Media (5) | 0.99% | — | Mcafee Application ControlMcafee Change Control | 22/8/2012 | 16/6/2026 | McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attributes of the password file, which allows local users to bypass authentication by executing a command. | |
| Modificada | Alta (7.1) | 1.0% | — | Cisco Application Control Engine Software | 20/6/2012 | 16/6/2026 | Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances, and read or… |