Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2016-20050
NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by suppl…
Netschedscan
No fix yet
CRITICAL 9.8
CVE-2024-25254
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
Superscan
No fix yet
MEDIUM 5.4
CVE-2023-5445
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter …
Epolicy Orchestrator
5.10.0+
HIGH 8.0
CVE-2023-5444
A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully ad…
Epolicy Orchestrator
5.10.0+
HIGH 7.2
CVE-2023-40352
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.
Safe Connect
2.16.1.126+
MEDIUM 6.1
CVE-2023-3946
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain …
Epolicy Orchestrator
5.10.0+
MEDIUM 6.7
CVE-2023-25134
McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model …
Total Protection
16.0.50+
MEDIUM 6.7
CVE-2023-0978
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary…
Advanced Threat Defense
after 4.14.2
MEDIUM 5.5
CVE-2023-24577
McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could en…
Total Protection
16.0.50+
MEDIUM 5.5
CVE-2023-24578
McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower priv…
Total Protection
16.0.49+
MEDIUM 5.5
CVE-2023-24579
McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.
Total Protection
16.0.51+
HIGH 7.8
CVE-2022-43751
McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to …
Total Protection
16.0.49+
MEDIUM 5.5
CVE-2022-2188
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak dir…
Data Exchange Layer
6.0.0.280+
MEDIUM 6.1
CVE-2022-3339
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain ac…
Epolicy Orchestrator
5.10.0+
MEDIUM 5.4
CVE-2022-3338
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Ser…
Epolicy Orchestrator
5.10.0+
MEDIUM 6.5
CVE-2022-2330
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause t…
Data Loss Prevention Endpoint
11.6.600.212 / 11.9.100+
HIGH 7.8
CVE-2022-37025
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuratio…
Security Scan Plus
4.1.262.1+
HIGH 7.3
CVE-2022-2313
A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain hig…
Agent
5.7.7+
HIGH 8.2
CVE-2022-1824
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a…
Consumer Product Removal Tool
10.4.128+
HIGH 7.8
CVE-2022-1823
Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a co…
Consumer Product Removal Tool
10.4.128+
MEDIUM 6.1
CVE-2022-1254
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.…
Web Gateway
7.8.2.31 / 8.2.27+
HIGH 7.2
CVE-2022-1258
A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrat…
Agent
5.7.6+
MEDIUM 5.5
CVE-2022-1257
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sens…
Agent
5.7.6+
HIGH 7.8
CVE-2022-1256
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn…
Agent
5.7.6+
MEDIUM 6.7
CVE-2022-0859
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during…
Epolicy Orchestrator
5.10.0+
MEDIUM 6.1
CVE-2022-0857
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker…
Epolicy Orchestrator
5.10.0+
MEDIUM 5.3
CVE-2022-0862
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…
Epolicy Orchestrator
5.10.0+
HIGH 7.3
CVE-2022-0815
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain acces…
Webadvisor
after 8.1.0.1895
HIGH 7.2
CVE-2021-4088
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a rem…
Data Loss Prevention
11.7.101 / 11.8.100+
HIGH 7.8
CVE-2021-31854
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cle…
Agent
5.7.5+