← Back

Mcafee

mcafee

602 CVEs • 137 products

Products (137)

Click to collapse
Toggle
Web Gateway
web_gateway
Agent
agent
Email Gateway
email_gateway
Gateway
gateway
Scan Engine
scan_engine
Virusscan
virusscan
Mcafee Agent
mcafee_agent
True Key
true_key
Virex
virex
Livesafe
livesafe
Cloud Av
cloud_av
Webadvisor
webadvisor
Cma
cma
Smartfilter
smartfilter
Superscan
superscan
Asset Manager
asset_manager
File Lock
file_lock
Getsusp
getsusp
Techcheck
techcheck
Asap Virusscan
asap_virusscan
Freescan
freescan
Mcinsctl.dll
mcinsctl.dll
Antispyware
antispyware
Quickclean
quickclean
Spamkiller
spamkiller
Network Agent
network_agent
Neotrace
neotrace
Visual Trace
visual_trace
Virusscan Plus
virusscan_plus

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 16, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
4.6 MEDIUM· v3
4.1 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
4.6 MEDIUM· v3
4.1 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
9.0 CRITICAL· v3
7.7 HIGH· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user in...Show more
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.Show less
1Mcafee
1Mcafee Agent
Jun 17, 2026
Sep 10, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
1Mcafee
1Mcafee Agent
Jun 17, 2026
Sep 10, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly a...Show more
Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.Show less
1Mcafee
1Mcafee Agent
Jun 17, 2026
Sep 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
1Mcafee
1Mcafee Agent
Jun 17, 2026
Sep 10, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.
1Mcafee
1Mvision Endpoint
Jun 17, 2026
Sep 9, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee f...Show more
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.Show less
1Mcafee
1Mvision Endpoint
Jun 17, 2026
Sep 9, 2020
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions.
1Mcafee
1Endpoint Security
Jun 17, 2026
Sep 9, 2020
N/A· v4
6.9 MEDIUM· v3
5.9 MEDIUM· v2
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain dete...Show more
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
Sep 9, 2020
N/A· v4
4.7 MEDIUM· v3
2.1 LOW· v2
Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive inf...Show more
Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
Sep 9, 2020
N/A· v4
7.3 HIGH· v3
2.1 LOW· v2
Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise...Show more
Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
Sep 9, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulat...Show more
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.Show less
1Mcafee
1True Key
Jun 17, 2026
Sep 4, 2020
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another...Show more
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another user’s passwords on the same machine via triggering a process dump in specific situations.Show less
1Mcafee
1Application And Change Control
Jun 17, 2026
Aug 26, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery sect...Show more
Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Aug 21, 2020
N/A· v4
6.9 MEDIUM· v3
3.3 LOW· v2
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic li...Show more
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic links to redirect a McAfee file operations to an unintended file.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing pla...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plai...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain textShow less