Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.40% | — | Trendmicro Serverprotect | 27/1/2021 | 17/6/2026 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scan engine component. An attacker must first obtain the ability to execute low-privileged code… | |
| Modificada | Media (5.5) | 0.40% | — | Trendmicro Serverprotect | 27/1/2021 | 17/6/2026 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scheduled scan component. An attacker must first obtain the ability to execute low-privileged… | |
| Modificada | Media (5.5) | 0.40% | — | Trendmicro Serverprotect | 27/1/2021 | 17/6/2026 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a manual scan component. An attacker must first obtain the ability to execute low-privileged code… | |
| Modificada | Crítica (9.8) | 64% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password. | |
| Modificada | Crítica (9.8) | 2.7% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root. | |
| Modificada | Alta (7.5) | 6.4% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access. | |
| Modificada | Alta (7.5) | 6.0% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths. | |
| Modificada | Media (4.8) | 1.1% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product. | |
| Modificada | Alta (8.8) | 1.1% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token. | |
| Modificada | Media (4.8) | 0.72% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product in a manner separate from the similar CVE-2020-8462. | |
| Modificada | Media (5.3) | 3.2% | — | Trendmicro Apex ONETrendmicro Officescan | 1/12/2020 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information. | |
| Modificada | Media (5.3) | 3.2% | — | Trendmicro Apex ONETrendmicro Officescan | 1/12/2020 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents. | |
| Modificada | Media (5.3) | 3.2% | — | Trendmicro Apex ONETrendmicro Officescan | 1/12/2020 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names. | |
| Modificada | Media (5.3) | 3.2% | — | Trendmicro Apex ONETrendmicro Officescan | 1/12/2020 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information. | |
| Modificada | Media (6.7) | 0.67% | — | Trendmicro Serverprotect | 1/12/2020 | 17/6/2026 | A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute high-privileged code on the target in order to exploit this vulnerability. | |
| Modificada | Media (5.3) | 3.2% | — | Trendmicro Apex ONETrendmicro Officescan | 1/12/2020 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server. | |
| Modificada | Alta (7.2) | 45% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (7.2) | 45% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (8.8) | 51% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges. | |
| Modificada | Crítica (9.8) | 73% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | Trendmicro Worry-free Business Security | 18/11/2020 | 17/6/2026 | A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console. | |
| Modificada | Alta (7.8) | 0.43% | — | Trendmicro Apex ONE | 18/11/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege. | |
| Modificada | Alta (7.8) | 0.57% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product. | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product. | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product. |