Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 17% | — | Vmware Carbon Black APP Control | 22/2/2023 | 17/6/2026 | VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating… | |
| Modificada | Crítica (9.1) | 1.5% | — | Vmware Carbon Black APP Control | 23/3/2022 | 17/6/2026 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where… | |
| Modificada | Crítica (9.1) | 20% | — | Vmware Carbon Black APP Control | 23/3/2022 | 17/6/2026 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute… | |
| Modificada | Crítica (9.8) | 11% | — | Vmware Carbon Black APP Control | 23/6/2021 | 17/6/2026 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate. | |
| Modificada | Crítica (9.1) | 1.4% | — | Vmware Carbon Black Cloud Workload | 1/4/2021 | 17/6/2026 | VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue… | |
| Modificada | Baja (3.6) | 0.21% | — | Vmware Carbon Black Cloud | 16/12/2020 | 17/6/2026 | The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation. | |
| Modificada | Media (5.5) | 0.44% | — | Carbonblack Carbon Black CB | 13/6/2018 | 17/6/2026 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will… | |
| Modificada | Crítica (9.8) | 1.7% | — | Carbonblack Carbon Black | 19/2/2018 | 17/6/2026 | A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions. | |
| Modificada | Alta (7.5) | 1.0% | — | Carbonblack Carbon Black | 12/2/2018 | 17/6/2026 | cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe. | |
| Modificada | Media (4.4) | 0.27% | — | Carbonblack Carbon Black | 12/2/2018 | 17/6/2026 | The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call. | |
| Modificada | Media (6.8) | 0.61% | — | Carbonblack Carbon Black | 22/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user. |