Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.0% | — | Ivanti Endpoint Manager Mobile | 8/9/2026 | 9/9/2026 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | |
| Analizada | Crítica (9.1) | 0.86% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled… | |
| Analizada | Alta (7.2) | 2.5% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 1.5% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods. | |
| Analizada | Crítica (9.1) | 0.85% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Media (5.5) | 0.62% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 30/9/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 8/7/2025 | 17/6/2026 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution | |
| Analizada | Alta (7.2) | 17% | — | Ivanti Endpoint Manager Mobile | 8/7/2025 | 17/6/2026 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution | |
| Analizada | Alta (8.8) | 87% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | |
| Analizada | Alta (7.8) | 0.24% | — | Ivanti Endpoint Manager Mobile | 8/10/2024 | 17/6/2026 | Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. | |
| Modificada | Alta (7.5) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources. | |
| Modificada | Alta (8.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | |
| Analizada | Media (6.5) | 0.94% | — | Ivanti Endpoint Manager Mobile | 7/8/2024 | 17/6/2026 | An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information | |
| Modificada | Media (6.7) | 1.1% | — | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance. | |
| Analizada | Media (6.7) | 1.1% | — | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. | |
| Analizada | Media (6.7) | 0.97% | — | Ivanti Endpoint Manager Mobile | 22/5/2024 | 17/6/2026 | An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database. | |
| Modificada | Crítica (9.1) | 1.9% | — | Ivanti Endpoint Manager Mobile | 15/11/2023 | 17/6/2026 | A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk,… |