Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2016-20050 NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by suppl… Netschedscan No fix yet Fix from $1,6002026-04-04 CRITICAL 9.8 CVE-2024-25254 SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter. Superscan No fix yet Fix from $2,3002024-11-11 MEDIUM 5.4 CVE-2023-5445 An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter … Epolicy Orchestrator 5.10.0+ Fix from $1,6002023-11-17 HIGH 8.0 CVE-2023-5444 A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully ad… Epolicy Orchestrator 5.10.0+ Fix from $1,9502023-11-17 HIGH 7.2 CVE-2023-40352 McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. Safe Connect 2.16.1.126+ Fix from $1,9502023-08-21 MEDIUM 6.1 CVE-2023-3946 A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain … Epolicy Orchestrator 5.10.0+ Fix from $1,6002023-07-26 MEDIUM 6.7 CVE-2023-25134 McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model … Total Protection 16.0.50+ Fix from $1,6002023-03-21 MEDIUM 6.7 CVE-2023-0978 A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary… Advanced Threat Defense after 4.14.2 Fix from $1,6002023-03-13 MEDIUM 5.5 CVE-2023-24577 McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could en… Total Protection 16.0.50+ Fix from $1,6002023-03-13 MEDIUM 5.5 CVE-2023-24578 McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower priv… Total Protection 16.0.49+ Fix from $1,6002023-03-13 MEDIUM 5.5 CVE-2023-24579 McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt. Total Protection 16.0.51+ Fix from $1,6002023-03-13 HIGH 7.8 CVE-2022-43751 McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to … Total Protection 16.0.49+ Fix from $1,9502022-11-23 MEDIUM 5.5 CVE-2022-2188 Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak dir… Data Exchange Layer 6.0.0.280+ Fix from $1,6002022-11-07 MEDIUM 6.1 CVE-2022-3339 A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain ac… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-10-18 MEDIUM 5.4 CVE-2022-3338 An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Ser… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-10-18 MEDIUM 6.5 CVE-2022-2330 Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause t… Data Loss Prevention Endpoint 11.6.600.212 / 11.9.100+ Fix from $1,6002022-08-30 HIGH 7.8 CVE-2022-37025 An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuratio… Security Scan Plus 4.1.262.1+ Fix from $1,9502022-08-18 HIGH 7.3 CVE-2022-2313 A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain hig… Agent 5.7.7+ Fix from $1,9502022-07-27 HIGH 8.2 CVE-2022-1824 An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a… Consumer Product Removal Tool 10.4.128+ Fix from $1,9502022-06-20 HIGH 7.8 CVE-2022-1823 Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a co… Consumer Product Removal Tool 10.4.128+ Fix from $1,9502022-06-20 MEDIUM 6.1 CVE-2022-1254 A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.… Web Gateway 7.8.2.31 / 8.2.27+ Fix from $1,6002022-04-20 HIGH 7.2 CVE-2022-1258 A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrat… Agent 5.7.6+ Fix from $1,9502022-04-14 MEDIUM 5.5 CVE-2022-1257 Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sens… Agent 5.7.6+ Fix from $1,6002022-04-14 HIGH 7.8 CVE-2022-1256 A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn… Agent 5.7.6+ Fix from $1,9502022-04-14 MEDIUM 6.7 CVE-2022-0859 McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 MEDIUM 6.1 CVE-2022-0857 A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 MEDIUM 5.3 CVE-2022-0862 A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 HIGH 7.3 CVE-2022-0815 Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain acces… Webadvisor after 8.1.0.1895 Fix from $1,9502022-03-10 HIGH 7.2 CVE-2021-4088 SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a rem… Data Loss Prevention 11.7.101 / 11.8.100+ Fix from $1,9502022-01-24 HIGH 7.8 CVE-2021-31854 A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cle… Agent 5.7.5+ Fix from $1,9502022-01-19