Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2018-6678
Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated adm…
Mcafee Web Gateway
No fix yet
MEDIUM 5.4
CVE-2018-6681
Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users…
Network Security Manager
after 9.1.7.11
CRITICAL 9.8
CVE-2018-6667
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exe…
Mcafee Web Gateway
after 7.8.1.5
MEDIUM 6.5
CVE-2018-6671
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authentica…
Epolicy Orchestrator
after 5.9.1
MEDIUM 6.5
CVE-2018-6672
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to v…
Epolicy Orchestrator
after 5.9.1
CRITICAL 9.8
CVE-2017-3907
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows…
Mcafee Threat Intelligence Exchange
Mitigation only
CRITICAL 9.8
CVE-2017-3936
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run a…
Epolicy Orchestrator
Mitigation only
CRITICAL 9.1
CVE-2017-3968
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Preventio…
Network Data Loss Prevention
8.2.7.42.2 / 9.3.4.1.5+
CRITICAL 9.8
CVE-2017-3962
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before…
Network Security Manager
8.2.7.42.2+
HIGH 8.8
CVE-2017-3960
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated u…
Network Security Manager
8.2.7.42.2+
MEDIUM 6.5
CVE-2018-6670
External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential info…
Common Catalog
2.0.3+
HIGH 7.8
CVE-2018-6662
Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a …
Management Of Native Encryption
4.1.4+
HIGH 8.8
CVE-2018-6664
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint befo…
Data Loss Prevention Endpoint
10.0.500 / 11.0.400+
MEDIUM 5.4
CVE-2017-3961
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated user…
Network Security Manager
8.2.7.42.2+
CRITICAL 9.8
CVE-2018-10381
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service est…
Tunnelbear
Mitigation only
HIGH 8.8
CVE-2017-3965
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42…
Network Security Manager
8.2.7.42.2+
MEDIUM 6.5
CVE-2017-3971
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential …
Network Security Manager
8.2.7.42.2+
MEDIUM 6.3
CVE-2017-3966
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Managemen…
Network Security Manager
8.2.7.42.2+
MEDIUM 6.1
CVE-2017-3967
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers…
Network Security Manager
8.2.7.42.2+
MEDIUM 5.9
CVE-2017-3969
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle at…
Network Security Manager
8.2.7.42.2+
MEDIUM 5.4
CVE-2017-3964
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attacke…
Network Security Manager
8.2.7.42.2+
CRITICAL 9.8
CVE-2017-3972
Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers …
Network Security Manager
8.2.7.42.2+
MEDIUM 5.4
CVE-2018-6659
Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to …
Epolicy Orchestrator
Mitigation only
HIGH 7.8
CVE-2018-6661
DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not …
True Key
after 4.20
HIGH 7.5
CVE-2017-3935
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the res…
Network Data Loss Prevention
after 9.3.0
MEDIUM 5.9
CVE-2017-3934
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-i…
Network Data Loss Prevention
after 9.3.0
MEDIUM 5.4
CVE-2017-3933
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view co…
Network Data Loss Prevention
Patch available
CRITICAL 9.8
CVE-2017-3897EPSS 12%
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security…
Livesafe
after 16.0.2
MEDIUM 5.9
CVE-2017-3898
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo…
Livesafe
after 16.0.2
CRITICAL 9.8
CVE-2017-4052
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated us…
Advanced Threat Defense
Patch available