Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
AnalizadaCrítica (9.8)1.1%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
AnalizadaCrítica (9.8)0.55%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
AnalizadaAlta (8.8)0.33%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaAlta (8.8)0.84%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
AnalizadaCrítica (9.8)13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
AnalizadaCrítica (9.8)13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
AnalizadaAlta (7.8)0.13%—Trendmicro Trend Micro Endpoint Encryption17/6/202517/6/2026
A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
ModificadaMedia (6.8)0.20%—Trendmicro Trend Micro Endpoint Encryption22/3/202317/6/2026
A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker…
ModificadaMedia (6.5)0.20%—Eset Endpoint EncryptionEset Full Disk Encryption6/9/202217/6/2026
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
ModificadaAlta (7.8)0.32%—Symantec Encryption DesktopSymantec Endpoint EncryptionSymantec Ghost Solution SuiteSymantec IT Management Suite8/1/202017/6/2026
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x…
ModificadaAlta (7.8)0.21%—Symantec Endpoint Encryption1/7/201917/6/2026
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
ModificadaAlta (7.8)0.21%—Symantec Endpoint Encryption1/7/201917/6/2026
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
ModificadaAlta (7.8)0.24%—Symantec Endpoint Encryption10/4/201917/6/2026
Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaMedia (6.8)0.33%—Symantec Endpoint Encryption13/11/201717/6/2026
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.
ModificadaMedia (4.5)0.27%—Symantec Endpoint Encryption13/11/201717/6/2026
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a denial of service (DoS) attack, which is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific…
ModificadaMedia (5.7)0.28%—Symantec Endpoint Encryption23/10/201717/6/2026
In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented programming, a memory leak may happen when an…
ModificadaMedia (4.2)0.29%—Symantec Endpoint Encryption10/10/201717/6/2026
A denial of service (DoS) attack in Symantec Endpoint Encryption before SEE 11.1.3HF2 allows remote attackers to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.
ModificadaAlta (7.8)0.29%—Symantec Endpoint Encryption14/5/201617/6/2026
Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
ModificadaBaja (2.3)0.32%—Symantec Endpoint Encryption18/12/201517/6/2026
EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.
ModificadaBaja (2.1)0.20%—Mcafee Endpoint Encryption FOR Files AND FoldersMcafee File AND Removable Media Protection29/10/201417/6/2026
The (1) Removable Media and (2) CD and DVD encryption offsite access options (formerly Endpoint Encryption for Removable Media or EERM) in McAfee File and Removable Media Protection (FRP) 4.3.0.x, and Endpoint Encryption for Files and Folders (EEFF) 3.2.x through 4.2.x, uses a hard-coded salt, which makes it easier…