Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2016-20050

Published Apr 4, 2026

NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-25254

Published Nov 11, 2024

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-5445

Published Nov 17, 2023

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5444

Published Nov 17, 2023

A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrato…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40352

Published Aug 21, 2023

McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3946

Published Jul 26, 2023

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25134

Published Mar 21, 2023

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry.…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24579

Published Mar 13, 2023

McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24578

Published Mar 13, 2023

McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24577

Published Mar 13, 2023

McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privile…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0221

Published Jan 13, 2023

Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43751

Published Nov 23, 2022

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be con…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3339

Published Oct 18, 2022

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3338

Published Oct 18, 2022

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37025

Published Aug 18, 2022

An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (L…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2313

Published Jul 27, 2022

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful pla…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1824

Published Jun 20, 2022

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1823

Published Jun 20, 2022

Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1254

Published Apr 20, 2022

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1258

Published Apr 14, 2022

A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1257

Published Apr 14, 2022

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through stor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1256

Published Apr 14, 2022

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 599 CVEsPage 1 of 24