Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mcafee

First CVE: Dec 22, 1999Active for: 27 yearsTotal CVEs: 605
51.8
VTI Score
TOP TARGET

McAfee's vulnerability footprint spans a broadly represented portfolio of enterprise security products including endpoint protection, network defense, and centralized management platforms that are pervasively deployed across large organizations. The vendor's disclosures cluster around application-layer weaknesses such as cross-site scripting, privilege-management flaws, and information-exposure issues, many of which carry elevated tendency toward public exploit availability. McAfee's products—notably ePolicy Orchestrator, Web Gateway, Endpoint Security, and its network data-loss prevention and virus-scanning tools—represent high-value consolidation points in security infrastructure where a vulnerability can affect detection, management, and enforcement across an entire environment. Defenders should treat McAfee advisories as affecting both detection bypass risk and administrative control, prioritizing updates to internet-facing or centrally managed instances. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
605
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mcafee over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 1999
26 years ago
Most Recent CVE
Apr 4, 2026
111 days ago

Products(137 total)

Top CVEs

Signals from CVEs in this vendor scope (605 CVEs).

605 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2006-5156HIGH
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/
Oct 5, 200610.082NOYES
CVE-2020-13935HIGH
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
CVE-2004-0230MEDIUM
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2004-0932HIGH
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
CVE-2012-1457MEDIUM
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Mar 21, 20124.370NONO
CVE-2012-1456MEDIUM
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.
Mar 21, 20124.369NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2012-1442MEDIUM
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky
Mar 21, 20124.369NONO
View all 605 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products605 CVEs
8%
51%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local179 (29.6%)
Network217 (35.9%)
Unknown186 (30.7%)
Physical7 (1.2%)
Adjacent Network16 (2.6%)
Attack Complexity
Low353 (58.3%)
High66 (10.9%)
Unknown186 (30.7%)
User Interaction
None308 (50.9%)
Unknown186 (30.7%)
Required111 (18.3%)
Privileges Required
Low181 (29.9%)
High77 (12.7%)
None161 (26.6%)
Unknown186 (30.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (605 CVEs).

CISA KEV
2 CVEs
0.3% of CVEs· 99th percentile
Metasploit
7 CVEs
1.2% of CVEs· 97th percentile
Nuclei
5 CVEs
0.8% of CVEs· 95th percentile
ExploitDB
59 CVEs
9.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mcafee.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mcafee — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mcafee's Products

View all 13 CNAs →

Top CWEs