Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.62%—Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+153/3/202117/6/2026
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ModificadaAlta (7.2)2.6%—Trendmicro Antivirus+ Security 2020Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2020Trendmicro Internet Security 2021+410/2/202117/6/2026
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability.
ModificadaAlta (7.8)0.43%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…
ModificadaMedia (5.5)0.89%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to…
ModificadaMedia (6.5)1.7%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.
ModificadaMedia (5.3)1.5%—Trendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.
ModificadaMedia (5.3)1.5%—Trendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of configuration informaiton.
ModificadaMedia (5.3)2.2%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.
ModificadaMedia (5.3)2.2%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information.
ModificadaMedia (5.3)1.9%—Trendmicro Apex ONETrendmicro Worry-free Business Security4/2/202117/6/2026
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.
ModificadaMedia (5.3)2.1%—Trendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port.
ModificadaMedia (5.3)1.6%—Trendmicro Apex ONE4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about the managing port used by agents.
ModificadaMedia (5.3)1.9%—Trendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro Officescan4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file.
ModificadaMedia (5.3)2.0%—Trendmicro Apex ONETrendmicro Officescan4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database.
ModificadaMedia (5.3)2.2%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro Officescan4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro Officescan4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.
ModificadaMedia (5.3)2.1%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.
ModificadaBaja (3.3)0.48%—Trendmicro Antivirus4/2/202117/6/2026
Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability that could lead to disabling all the scanning functionality within the application. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaAlta (7.8)0.75%—Trendmicro Housecall FOR Home Networks27/1/202117/6/2026
A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the machine to exploit this vulnerability.