Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.0%—Ivanti Endpoint Manager Mobile8/9/20269/9/2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Pendiente de análisisAlta (8.1)1.5%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
Pendiente de análisisAlta (7.7)0.72%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Pendiente de análisisAlta (7.5)1.6%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
AnalizadaMedia (5.9)0.26%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
AnalizadaAlta (8.6)0.25%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.
AnalizadaAlta (8.8)1.6%—Ivanti Endpoint Manager12/5/202617/6/2026
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
AnalizadaAlta (7.8)0.37%—Ivanti Endpoint Manager12/5/202617/6/2026
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
AnalizadaMedia (6.5)1.1%—Ivanti Endpoint Manager12/5/202617/6/2026
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
AnalizadaCrítica (9.1)0.86%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled…
AnalizadaAlta (7.2)2.5%⚠ Explotación activaIvanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
AnalizadaCrítica (9.8)1.5%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
AnalizadaCrítica (9.1)0.85%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
AnalizadaAlta (8.8)1.2%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
AnalizadaCrítica (9.3)0.86%—Motex Lanscope Endpoint Manager25/2/202617/6/2026
Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.
AnalizadaAlta (7.5)88%⚠ Explotación activaIvanti Endpoint Manager10/2/202617/6/2026
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
AnalizadaMedia (6.5)0.73%—Ivanti Endpoint Manager10/2/202617/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
AnalizadaCrítica (9.8)99%⚠ Explotación activaIvanti Endpoint Manager Mobile29/1/202617/6/2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
AnalizadaCrítica (9.8)99%⚠ Explotación activaIvanti Endpoint Manager Mobile29/1/202617/6/2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
AplazadaMedia (6.9)0.27%—Freepbx Endpoint ManagerAI10/12/202525/9/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this…
AnalizadaAlta (7.8)0.58%—Ivanti Endpoint Manager9/12/202517/6/2026
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.
AnalizadaAlta (8)1.4%—Ivanti Endpoint Manager9/12/202517/6/2026
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
AnalizadaAlta (8.8)2.0%—Ivanti Endpoint Manager9/12/202517/6/2026
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
AnalizadaMedia (6.1)33%—Ivanti Endpoint Manager9/12/202517/6/2026
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
AnalizadaAlta (7.1)0.24%—Ivanti Endpoint Manager11/11/202517/6/2026
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk