CVE Tools

Endpoint Security

104 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Endpoint Security, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Endpoint Security CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Endpoint Security CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-071
2026-080
2026-090

Severity

How the 104 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High4341%
  • Medium5351%
  • Low66%

Latest CVEs

The 15 most recently published vulnerabilities affecting Endpoint Security.

  1. CVE-2026-56152Incorrect Authorization in Kibana Leading to Information Disclosure5.3
  2. CVE-2025-14963A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vuln...7.8
  3. CVE-2025-5317Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac5.5
  4. CVE-2023-46669Elastic Agent / Elastic Endpoint Security local API key disclosure6.2
  5. CVE-2024-8424WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM7.8
  6. CVE-2024-3779Denial of Service in ESET products for Windows6.1
  7. CVE-2024-2224Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)8.1
  8. CVE-2024-2223 Incorrect Regular Expression in GravityZone Update Server (VA-11465)8.1
  9. CVE-2024-0353Local privilege escalation in Windows products7.8
  10. CVE-2023-7043Unquoted path privilege vulnerability in ESET products for Windows3.3
  11. CVE-2024-0316Improper cleanup vulnerability in FireEye Endpoint Security6.8
  12. CVE-2023-5594Improper following of a certificate's chain of trust in ESET security products7.5
  13. CVE-2023-28134Local Privliege Escalation in Check Point Endpoint Security Remediation Service7.8
  14. CVE-2023-3665 A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service ...5.5
  15. CVE-2023-3160Local privilege escalation in security products for Windows7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store