Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.4% | 💥 Exploit | Pcprotect Antivirus | 28/9/2018 | 17/6/2026 | PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse. | |
| Modificada | Alta (7.8) | 1.1% | — | Eset CompusecEset Deslock+ PROEset Internet SecurityEset Nod32 Antivirus+2 | 7/9/2018 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan… | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability. | |
| Modificada | Alta (7.8) | 0.41% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the… | |
| Modificada | Alta (7.8) | 0.76% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the… | |
| Modificada | Alta (7.8) | 1.2% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 25/7/2018 | 17/6/2026 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00… | |
| Modificada | Crítica (9.8) | 3.4% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security+2 | 6/7/2018 | 17/6/2026 | A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes. | |
| Modificada | Alta (7) | 0.29% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.45% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Media (5.5) | 0.66% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability… | |
| Modificada | Alta (7.8) | 0.49% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222060 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.49% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x22205C by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Baja (3.3) | 1.7% | 💥 Exploit | Teclib-edition Armadito Antivirus | 21/2/2018 | 17/6/2026 | An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters… | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2208C0. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x221808. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220840. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008254. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00824C. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00825C. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A0081DC. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008264. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A0081E4. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008240. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008268. | |
| Modificada | Alta (7.8) | 0.40% | — | Jiangmin Antivirus | 6/2/2018 | 17/6/2026 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220400. |