mcafee

602 tracked vulnerabilities.

CVE-2020-7336 MEDIUM
McAfee Network Security Management < 9.2.9.55 - Cross-Site Request Forgery
Jan 05, 2021
CVSS 6.6
EPSS 0.00
CVE-2020-7339 MEDIUM
McAfee Database Security < 4.8.0 - Use of a Broken or Risky Cryptographic Algorithm via SHA1 Signed Certificate
Dec 10, 2020
CVSS 6.3
EPSS 0.00
CVE-2020-7337 MEDIUM
McAfee VirusScan Enterprise < 8.8 Patch 16 - Local Security Bypass via Windows Defender Application Control
Dec 09, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-7335 HIGH
McAfee Total Protection < 16.0.29 - Privilege Escalation via Junction Link Timing Attack
Dec 01, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7333 MEDIUM
McAfee Endpoint Security < 10.7.0 - Authenticated Cross-Site Scripting in Firewall ePO Extension Configuration Wizard
Nov 12, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-7332 HIGH
McAfee Endpoint Security < 10.6.1 - Cross-Site Request Forgery in Firewall ePO Extension
Nov 12, 2020
CVSS 7.0
EPSS 0.00
CVE-2020-7331 HIGH
McAfee Endpoint Security < 10.6.1 - Unquoted Service Path Denial of Service and Malicious File Execution
Nov 12, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7329 HIGH
McAfee MVISION Endpoint < 20.11 - Server-Side Request Forgery via XML File Processing
Nov 11, 2020
CVSS 7.2
EPSS 0.01
CVE-2020-7328 HIGH
McAfee MVISION Endpoint < 20.11 - Server-Side Request Forgery via ePO Extension HTTP Request
Nov 11, 2020
CVSS 7.2
EPSS 0.01
CVE-2020-14792 MEDIUM
Oracle Java SE <15 - Info Disclosure
Oct 21, 2020
CVSS 4.2
EPSS 0.00
CVE-2020-14782 LOW
Oracle Java SE <15 - Unauthorized Update
Oct 21, 2020
CVSS 3.7
EPSS 0.00
CVE-2020-7327 MEDIUM
McAfee MVISION Endpoint Detection and Response Client < 3.2.0 - Authentication Bypass via Windows Service Manipulation
Oct 15, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-7326 MEDIUM
McAfee Active Response < 2.4.4 - Authentication Bypass via Windows Service Manipulation
Oct 15, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-7334 HIGH
McAfee Application and Change Control < 8.3.2 - Improper Privilege Assignment via MSI Installer
Oct 15, 2020
CVSS 7.7
EPSS 0.00
CVE-2020-7318 MEDIUM NUCLEI
McAfee ePolicy Orchestrator 5.10.0-5.10.8 - Authenticated Stored Cross-Site Scripting via Administrator Input Parameters
Oct 14, 2020
CVSS 4.6
EPSS 0.13
CVE-2020-7317 MEDIUM
McAfee ePolicy Orchestrator < 5.9.1 - Cross-Site Scripting via syncPointList Parameter
Oct 14, 2020
CVSS 4.6
EPSS 0.00
CVE-2020-7330 HIGH
McAfee Total Protection < 4.0.176.1 - Privilege Escalation via Environment Variable Manipulation
Oct 14, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7316 MEDIUM
McAfee File and Removable Media Protection < 5.3.0 - Unquoted Service Path Privilege Escalation
Oct 07, 2020
CVSS 6.6
EPSS 0.00
CVE-2020-7268 MEDIUM
McAfee Email Gateway < 7.6.406 - Path Traversal via External Input
Sep 16, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-7297 MEDIUM
McAfee Web Gateway 7.8.0-7.8.2.22 - Authenticated Privilege Escalation via User Interface
Sep 16, 2020
CVSS 5.7
EPSS 0.00
CVE-2020-7296 MEDIUM
McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via User Interface
Sep 15, 2020
CVSS 5.7
EPSS 0.00
CVE-2020-7295 LOW
McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via Log Data Access Controls
Sep 15, 2020
CVSS 3.5
EPSS 0.00
CVE-2020-7294 MEDIUM
McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via REST Interface
Sep 15, 2020
CVSS 4.6
EPSS 0.00
CVE-2020-7293 CRITICAL
McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via User Interface
Sep 15, 2020
CVSS 9.0
EPSS 0.00
CVE-2020-7315 MEDIUM
McAfee Agent < 5.6.6 - DLL Injection via Untrusted Search Path
Sep 10, 2020
CVSS 6.0
EPSS 0.00