Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.9)0.44%—Steeltoe.management.endpointAI17/9/202623/9/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query…
AplazadaAlta (8.8)0.51%—BE Rest EndpointsAI12/9/202614/9/2026
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any…
Pendiente de análisisAlta (8.7)0.13%—Netskope Endpoint DLPAI10/9/202618/9/2026
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation…
Pendiente de análisisMedia (6)0.11%—Netskope ClientAINetskope Endpoint DLPAI10/9/202618/9/2026
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could…
AnalizadaAlta (8.8)1.0%—Ivanti Endpoint Manager Mobile8/9/20269/9/2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Pendiente de análisisMedia (6.3)0.38%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Pendiente de análisisMedia (5)0.29%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Pendiente de análisisMedia (6.3)0.38%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Pendiente de análisisMedia (5.7)0.35%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
Pendiente de análisisAlta (7.3)0.13%—Beyondtrust Endpoint Privilege ManagementAI17/8/202618/8/2026
A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds.
Pendiente de análisisMedia (4.8)0.16%—Forcepoint ONE EndpointAI13/8/20263/9/2026
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
AnalizadaMedia (5.5)0.48%—Microsoft Defender FOR Endpoint11/8/202617/8/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Pendiente de análisisAlta (8.1)1.5%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
Pendiente de análisisAlta (7.7)0.72%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Pendiente de análisisAlta (7.5)1.6%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
AnalizadaAlta (7.5)0.46%—Cisco Secure Endpoint7/8/202619/8/2026
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during…
Pendiente de análisisCrítica (9.3)0.18%—Sophos Endpoint FOR MacosAISophos Home FOR MacosAI6/8/20261/9/2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Pendiente de análisisCrítica (9.3)1.4%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
Pendiente de análisisCrítica (9.3)1.3%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
Pendiente de análisisCrítica (9.3)1.3%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
AnalizadaMedia (5.9)0.26%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
AnalizadaAlta (8.6)0.25%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.
Pendiente de análisisMedia (4.3)0.65%—Zohocorp Manageengine Endpoint CentralAI21/7/202621/7/2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
AnalizadaAlta (7)0.23%—Microsoft Defender FOR Endpoint14/7/202622/7/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.20%—Microsoft Defender FOR Endpoint14/7/202622/7/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.