CVE Tools

Mcafee

485 CVEs tracked since 2000. Since Jan 2014, 2 of them reached CISA KEV.

Mcafee CVEs per month

Jan 2014 to Apr 2022. Point at a month, or focus the strip and use the arrow keys.
Mcafee CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0140
2014-0210
2014-0350
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-0810
2014-09null or fewer
2014-10200
2014-11null or fewer
2014-12null or fewer
2015-0120
2015-0260
2015-0340
2015-0430
2015-0510
2015-0620
2015-07null or fewer
2015-08null or fewer
2015-0930
2015-1010
2015-11null or fewer
2015-1220
2016-0140
2016-0210
2016-0310
2016-0430
2016-05100
2016-0630
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-0220
2017-03350
2017-04null or fewer
2017-0590
2017-06null or fewer
2017-0750
2017-08null or fewer
2017-0920
2017-1030
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06100
2018-0750
2018-08null or fewer
2018-0950
2018-1020
2018-11null or fewer
2018-12110
2019-01null or fewer
2019-0280
2019-03null or fewer
2019-04null or fewer
2019-0520
2019-06null or fewer
2019-07130
2019-08120
2019-0960
2019-1070
2019-11110
2019-1230
2020-0150
2020-0230
2020-0350
2020-04null or fewer
2020-05null or fewer
2020-0680
2020-07null or fewer
2020-08110
2020-09170
2020-1090
2020-1150
2020-1230
2021-0151
2021-02101
2021-03null or fewer
2021-0470
2021-0530
2021-06110
2021-0730
2021-08null or fewer
2021-0970
2021-1040
2021-1150
2021-12null or fewer
2022-0150
2022-02null or fewer
2022-0380
2022-0440

Products

The products that kept showing up in Mcafee's monthly top three, with their CVEs summed over those months.

  1. Epolicy Orchestrator4416 months
  2. Web Gateway308 months
  3. Network Data Loss Prevention293 months
  4. Data Loss Prevention Endpoint197 months
  5. Advanced Threat Defense185 months
  6. Agent188 months
  7. Virusscan Enterprise154 months
  8. Endpoint Security146 months
  9. Advanced Threat Defense (Atd)122 months
  10. Mcafee Web Gateway (Mwg)114 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Mcafee.

  1. CVE-2016-20050NetSchedScan 1.0 Buffer Overflow Denial of Service6.2
  2. CVE-2024-25254SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.9.8
  3. CVE-2023-5445 An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) t...5.4
  4. CVE-2023-5444CSRF in ePO leading to privilege escalation8.0
  5. CVE-2023-40352McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.7.2
  6. CVE-2023-3946 A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by con...5.4
  7. CVE-2023-25134McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result i...6.7
  8. CVE-2023-0978 A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially craf...6.4
  9. CVE-2023-24577McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute una...5.5
  10. CVE-2023-24578McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks.5.5
  11. CVE-2023-24579McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.5.5
  12. CVE-2023-0221Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the util...4.4
  13. CVE-2022-43751McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an un...7.8
  14. CVE-2022-2188DXL Broker privilege escalation vulnerability6.5
  15. CVE-2022-3338XXE in Trellix ePO server5.4

The record

Peak rank
#6 in Aug 2012
Busiest month shown
Mar 2017, 35 CVEs
Months with a KEV entry
2 since Jan 2014
Monthly snapshots
104 since 2000
Mcafee's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store