Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 7.1% | — | Sangfor Endpoint Detection AND ResponseAI | 24/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to… | |
| Modificada | Media (5.5) | 0.28% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier. | |
| Modificada | Alta (7.8) | 0.31% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger. | |
| Modificada | Alta (7.8) | 0.23% | — | Cybereason Endpoint Detection AND Response | 20/1/2023 | 9/7/2026 | Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elevated privileges. | |
| Modificada | Crítica (9.8) | 0.74% | — | Symantec Endpoint Detection AND Response | 8/11/2022 | 17/6/2026 | Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or… | |
| Modificada | Alta (7.5) | 0.40% | — | F-secure Elements Endpoint Detection AND ResponseF-secure Elements Endpoint ProtectionF-secure AtlantF-secure Internet Gatekeeper+2 | 12/10/2022 | 17/6/2026 | Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash. | |
| Modificada | Alta (7.5) | 0.48% | — | F-secure Elements Endpoint Detection AND ResponseF-secure Elements Endpoint ProtectionF-secure AtlantF-secure Cloud Protection FOR Salesforce+4 | 10/8/2022 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine crash. The exploit can be triggered remotely by an attacker. | |
| Modificada | Alta (7.5) | 0.48% | — | F-secure Elements Endpoint Detection AND ResponseF-secure Elements Endpoint ProtectionF-secure AtlantF-secure Cloud Protection FOR Salesforce+4 | 5/8/2022 | 17/6/2026 | A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker. | |
| Modificada | Media (6.5) | 0.54% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements Collaboration ProtectionF-secure Internet Gatekeeper+3 | 25/5/2022 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker. | |
| Modificada | Media (5.3) | 0.66% | — | F-secure AtlantF-secure Internet GatekeeperF-secure Linux SecurityF-secure Security Cloud+2 | 9/2/2022 | 17/6/2026 | A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine. | |
| Modificada | Media (5.5) | 0.46% | — | F-secure AtlantF-secure Internet GatekeeperF-secure Linux SecurityF-secure Linux Security 64+2 | 22/12/2021 | 17/6/2026 | A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine. | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus… | |
| Modificada | Alta (7.5) | 2.0% | — | Symantec Endpoint Detection AND Response | 18/11/2020 | 17/6/2026 | Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Modificada | Media (6.7) | 0.29% | — | Mcafee Mvision Endpoint Detection AND Response | 15/10/2020 | 17/6/2026 | Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than… | |
| Modificada | Alta (7.5) | 2.0% | — | Symantec Endpoint Detection AND Response | 8/7/2020 | 17/6/2026 | Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Endpoint Detection AND Response | 8/5/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Endpoint Detection AND Response | 8/5/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | |
| Modificada | Alta (7.8) | 0.25% | — | Mcafee Endpoint Detection AND Response | 8/5/2020 | 17/6/2026 | Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to. | |
| Modificada | Media (6.1) | 1.4% | — | Symantec Endpoint Detection AND ResponseFedoraproject Fedora | 13/1/2020 | 17/6/2026 | Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access… |