Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.52% | — | Trendmicro Housecall FOR Home Networks | 29/9/2021 | 17/6/2026 | An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first… | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Maximum Security 2019Trendmicro Maximum Security 2020Trendmicro Maximum Security 2021Trendmicro Security FOR Best BUY | 6/9/2021 | 17/6/2026 | Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. | |
| Modificada | Alta (8.8) | 4.3% | — | Trendmicro Apex ONETrendmicro Officescan | 4/8/2021 | 17/6/2026 | An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Modificada | Alta (7.8) | 0.59% | — | Trendmicro Apex ONETrendmicro Officescan | 4/8/2021 | 17/6/2026 | An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code… | |
| Analizada | Alta (7.8) | 1.5% | ⚠ Explotación activa | Trendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security | 29/7/2021 | 17/6/2026 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.8) | 5.0% | ⚠ Explotación activa | Trendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security | 29/7/2021 | 17/6/2026 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management… | |
| Modificada | Alta (7.8) | 0.36% | — | Trendmicro Apex ONETrendmicro Worry-free Business Security | 20/7/2021 | 17/6/2026 | An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on affected installations. Please note: an… | |
| Modificada | Alta (8.8) | 5.2% | — | Trendmicro Password Manager | 8/7/2021 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit… | |
| Modificada | Alta (7.8) | 0.37% | — | Trendmicro Password Manager | 8/7/2021 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must first obtain the ability to execute… | |
| Modificada | Media (5.4) | 1.4% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/6/2021 | 17/6/2026 | Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal. | |
| Modificada | Alta (7.8) | 0.30% | — | Trendmicro Maximum Security 2021 | 3/6/2021 | 17/6/2026 | The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user privileges and access on the machine to… | |
| Modificada | Media (6.5) | 0.96% | — | Trendmicro Home Network Security | 27/5/2021 | 17/6/2026 | Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Home Network Security | 27/5/2021 | 17/6/2026 | Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged… | |
| Modificada | Alta (7.8) | 0.43% | — | Trendmicro Home Network Security | 26/5/2021 | 17/6/2026 | Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. An attacker must first obtain the ability to execute low-privileged code on the… | |
| Modificada | Alta (7.3) | 0.35% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please… | |
| Modificada | Alta (7.3) | 0.26% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that… | |
| Modificada | Alta (8.1) | 3.9% | — | Trendmicro IM Security | 10/5/2021 | 17/6/2026 | A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface. | |
| Modificada | Alta (7.5) | 1.1% | — | Trendmicro Home Network Security | 5/5/2021 | 17/6/2026 | Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517. | |
| Modificada | Alta (7.5) | 1.1% | — | Trendmicro Home Network Security | 5/5/2021 | 17/6/2026 | Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31518. | |
| Modificada | Alta (7.8) | 0.53% | — | Trendmicro Antivirus | 22/4/2021 | 17/6/2026 | Trend Micro Antivirus for Mac 2020 v10.5 and 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first… | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Password Manager | 13/4/2021 | 17/6/2026 | Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program. | |
| Modificada | Media (5.5) | 0.42% | — | Trendmicro Apex ONETrendmicro Officescan | 13/4/2021 | 17/6/2026 | An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations. | |
| Modificada | Alta (7.8) | 0.51% | — | Trendmicro Apex ONETrendmicro Officescan | 13/4/2021 | 17/6/2026 | An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Trendmicro Apex ONETrendmicro Officescan | 13/4/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Modificada | Alta (7.8) | 0.51% | — | Trendmicro Apex ONETrendmicro Officescan | 13/4/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the… |