Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netschedscan MEDIUM 5.5
CVE-2016-20050

NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by suppl…

No fix yet
Fix from $1,600 2026-04-04
Superscan CRITICAL 9.8
CVE-2024-25254

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

No fix yet
Fix from $2,300 2024-11-11
Epolicy Orchestrator MEDIUM 5.4
CVE-2023-5445

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter …

Fix: 5.10.0+
Fix from $1,600 2023-11-17
Epolicy Orchestrator HIGH 8.0
CVE-2023-5444

A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully ad…

Fix: 5.10.0+
Fix from $1,950 2023-11-17
Safe Connect HIGH 7.2
CVE-2023-40352

McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.

Fix: 2.16.1.126+
Fix from $1,950 2023-08-21
Epolicy Orchestrator MEDIUM 6.1
CVE-2023-3946

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain …

Fix: 5.10.0+
Fix from $1,600 2023-07-26
Total Protection MEDIUM 6.7
CVE-2023-25134

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model …

Fix: 16.0.50+
Fix from $1,600 2023-03-21
Advanced Threat Defense MEDIUM 6.7
CVE-2023-0978

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary…

Fix: after 4.14.2
Fix from $1,600 2023-03-13
Total Protection MEDIUM 5.5
CVE-2023-24577

McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could en…

Fix: 16.0.50+
Fix from $1,600 2023-03-13
Total Protection MEDIUM 5.5
CVE-2023-24578

McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower priv…

Fix: 16.0.49+
Fix from $1,600 2023-03-13
Total Protection MEDIUM 5.5
CVE-2023-24579

McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.

Fix: 16.0.51+
Fix from $1,600 2023-03-13
Total Protection HIGH 7.8
CVE-2022-43751

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to …

Fix: 16.0.49+
Fix from $1,950 2022-11-23
Data Exchange Layer MEDIUM 5.5
CVE-2022-2188

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak dir…

Fix: 6.0.0.280+
Fix from $1,600 2022-11-07
Epolicy Orchestrator MEDIUM 6.1
CVE-2022-3339

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain ac…

Fix: 5.10.0+
Fix from $1,600 2022-10-18
Epolicy Orchestrator MEDIUM 5.4
CVE-2022-3338

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Ser…

Fix: 5.10.0+
Fix from $1,600 2022-10-18
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2022-2330

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause t…

Fix: 11.6.600.212 / 11.9.100+
Fix from $1,600 2022-08-30
Security Scan Plus HIGH 7.8
CVE-2022-37025

An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuratio…

Fix: 4.1.262.1+
Fix from $1,950 2022-08-18
Agent HIGH 7.3
CVE-2022-2313

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain hig…

Fix: 5.7.7+
Fix from $1,950 2022-07-27
Consumer Product Removal Tool HIGH 8.2
CVE-2022-1824

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a…

Fix: 10.4.128+
Fix from $1,950 2022-06-20
Consumer Product Removal Tool HIGH 7.8
CVE-2022-1823

Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a co…

Fix: 10.4.128+
Fix from $1,950 2022-06-20
Web Gateway MEDIUM 6.1
CVE-2022-1254

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.…

Fix: 7.8.2.31 / 8.2.27+
Fix from $1,600 2022-04-20
Agent HIGH 7.2
CVE-2022-1258

A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrat…

Fix: 5.7.6+
Fix from $1,950 2022-04-14
Agent MEDIUM 5.5
CVE-2022-1257

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sens…

Fix: 5.7.6+
Fix from $1,600 2022-04-14
Agent HIGH 7.8
CVE-2022-1256

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn…

Fix: 5.7.6+
Fix from $1,950 2022-04-14
Epolicy Orchestrator MEDIUM 6.7
CVE-2022-0859

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Epolicy Orchestrator MEDIUM 6.1
CVE-2022-0857

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Epolicy Orchestrator MEDIUM 5.3
CVE-2022-0862

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Webadvisor HIGH 7.3
CVE-2022-0815

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain acces…

Fix: after 8.1.0.1895
Fix from $1,950 2022-03-10
Data Loss Prevention HIGH 7.2
CVE-2021-4088

SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a rem…

Fix: 11.7.101 / 11.8.100+
Fix from $1,950 2022-01-24
Agent HIGH 7.8
CVE-2021-31854

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cle…

Fix: 5.7.5+
Fix from $1,950 2022-01-19