Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.20% | — | Wygk Copyright-safeguard-footer-noticeAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wygk Copyright Safeguard Footer Notice copyright-safeguard-footer-notice allows Stored XSS.This issue affects Copyright Safeguard Footer Notice: from n/a through <= 3.0. | |
| Aplazada | Media (5.3) | 0.15% | — | Oneidentity Safeguard FOR Privileged SessionsAI | 24/10/2024 | 17/6/2026 | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information. | |
| Aplazada | Crítica (9.8) | 51% | — | Oneidentity Safeguard FOR Privileged PasswordsAI | 30/8/2024 | 17/6/2026 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. | |
| Modificada | Alta (7) | 0.32% | — | HP Nonstop Safeguard H SeriesHP Nonstop Safeguard J SeriesHP Nonstop Safeguard L SeriesHP Nonstop Standard Security H Series+2 | 10/5/2019 | 17/6/2026 | A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x802022E0. By crafting an input buffer we can control the execution path to the point where the constant 0x12 will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x8020601C. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.54% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202014. By crafting an input buffer we can control the execution path to the point where the constant 0xFFFFFFF will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.60% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via multiple IOCTLs, e.g., 0x8810200B, 0x8810200F, 0x8810201B, 0x8810201F, 0x8810202B, 0x8810202F, 0x8810203F, 0x8810204B, 0x88102003, 0x88102007, 0x88102013,… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206024. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202298. By crafting an input buffer we can control the execution path to the point where the nt!memset function is called to zero out contents of a… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206040. By crafting an input buffer we can control the execution path to the point where the constant DWORD 0 will be written to a user-controlled… | |
| Modificada | Alta (9) | 2.0% | — | HP Nonstop Safeguard Security | 25/5/2015 | 17/6/2026 | Unspecified vulnerability in HP NonStop Safeguard Security Software H06.x, L15.02, and J06.x before J06.19 allows remote authenticated users to gain privileges by leveraging Expand access. | |
| Modificada | Media (4) | 2.1% | — | HP Nonstop Safeguard Security | 12/8/2014 | 17/6/2026 | HP NonStop Safeguard Security Software G, H06.03 through H06.28.01, and J06.03 through J06.17.01 does not properly evaluate the DISKFILE-PATTERN ACL of a program object file, which allows remote authenticated users to bypass intended restrictions on program access via vectors related to process-creation time. | |
| Modificada | Alta (9.3) | 4.2% | — | AVG SafeguardAVG Secure Search Toolbar | 8/7/2014 | 17/6/2026 | ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs… | |
| Modificada | Media (6.9) | 0.49% | — | Sophos Free EncryptionSophos Safeguard Privatecrypto | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this… | |
| Modificada | Baja (3.3) | 0.45% | — | Sophos Safeguard Enterprise | 29/8/2012 | 16/6/2026 | The Device Encryption Client component in Sophos SafeGuard Enterprise 6.0, when a volume-based encryption policy is enabled in conjunction with a user-defined key, does not properly block use of exFAT USB flash drives, which makes it easier for local users to bypass intended access restrictions and copy sensitive… | |
| Modificada | Media (6.9) | 0.34% | — | Sophos Safeguard Enterprise Device EncryptionSophos Safeguard Easy Device Encryption ClientSophos Disk Encryption | 24/8/2012 | 16/6/2026 | Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk… | |
| Modificada | Alta (7.8) | 0.32% | — | Utimaco Safeguard | 7/3/2007 | 16/6/2026 | The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive. |