Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 300 respecto a la semana anterior
Críticas / altas1352▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.30%—Elastic Endpoint Security1/7/20264/9/2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
En análisisMedia (6.2)0.10%—Trellix Endpoint Security24/2/202617/6/2026
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security…
AnalizadaAlta (8.8)0.17%—Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+110/12/202517/6/2026
A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,…
AplazadaMedia (5.1)0.18%—Kaspersky Endpoint Security FOR LinuxAIKaspersky Industrial Cybersecurity FOR Linux NodesAIKaspersky Endpoint Security FOR MACAI20/11/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and…
AnalizadaMedia (6.8)0.10%—Bitdefender Endpoint Security11/11/202517/6/2026
An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory…
AplazadaAlta (7.1)0.15%—Opswat Metadefender Endpoint Security SDKAIPaloaltonetworks GlobalprotectAI14/5/202517/6/2026
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the…
AnalizadaAlta (7.1)0.20%—Elastic AgentElastic Endpoint Security1/5/202517/6/2026
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by…
AnalizadaAlta (8.8)0.57%—Qianxin Tianqing Endpoint Security Management System21/4/202517/6/2026
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.
AplazadaMedia (5.3)0.13%—Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+96/2/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,…
ModificadaMedia (5.5)0.20%—Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+416/7/202417/6/2026
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
AnalizadaCrítica (9.8)0.73%—Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center9/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender…
AnalizadaCrítica (9.8)0.52%—Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center9/4/202417/6/2026
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089…
ModificadaAlta (7.8)0.55%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+515/2/202417/6/2026
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
ModificadaAlta (7.8)0.09%—Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server6/2/202417/6/2026
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in…
ModificadaMedia (5.5)0.28%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+231/1/202417/6/2026
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
ModificadaAlta (7.5)0.32%—Fireeye Endpoint Security15/1/202417/6/2026
Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.
ModificadaMedia (6.1)0.42%—Trellix Endpoint Security WEB Control10/1/202417/6/2026
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
ModificadaAlta (8.6)0.38%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+521/12/202317/6/2026
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
ModificadaAlta (7.3)0.15%—Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server16/11/202317/6/2026
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a…
ModificadaAlta (7.8)0.24%—Checkpoint Endpoint Security12/11/202317/6/2026
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ModificadaAlta (7.8)0.23%—Trellix Endpoint Security4/10/202317/6/2026
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
ModificadaAlta (7.8)0.18%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+414/8/202317/6/2026
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
ModificadaAlta (7.8)5.7%—Checkpoint Endpoint Security23/7/202317/6/2026
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
ModificadaMedia (4.3)0.39%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.
ModificadaMedia (5.5)0.19%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.