Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)7.4%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.
ModificadaMedia (4.4)1.8%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
ModificadaMedia (5.5)18%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.
ModificadaMedia (5.5)3.5%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained…
ModificadaMedia (4.9)6.5%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this…
ModificadaAlta (8.8)1.9%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker-controlled web page. An attacker must already have…
ModificadaMedia (4.4)0.90%—Trendmicro Antivirus30/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this…
ModificadaMedia (6.4)0.32%—Trendmicro Antivirus30/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute high-privileged code on the target system in…
ModificadaMedia (4.4)0.44%—Trendmicro Antivirus14/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implements an API with several properties that can be read and written to allowing the attacker to gather and modify sensitive product and user data. An attacker must first obtain the…
ModificadaMedia (6)0.60%—Trendmicro Antivirus14/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could supply a kernel pointer and leak several bytes of memory. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
ModificadaMedia (5.4)1.3%—Trendmicro Antivirus14/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass the Web Threat Protection feature of the product. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ModificadaBaja (3.3)0.85%—Trendmicro Antivirus13/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in which a Internationalized Domain Name homograph attack (Puny-code) could be used to add a malicious website to the approved websites list of Trend Micro Antivirus for Mac to bypass the web threat protection feature.
ModificadaAlta (7.8)0.62%—Trendmicro Antivirus2/10/202017/6/2026
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaMedia (6.3)0.30%—Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202029/9/202017/6/2026
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
ModificadaMedia (4.3)2.1%—Trendmicro Apex ONE29/9/202017/6/2026
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to exploit this vulnerability in that the target must visit a…
ModificadaAlta (7.8)2.4%—Trendmicro Apex ONE29/9/202017/6/2026
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.
ModificadaMedia (5.5)1.3%—Trendmicro Apex ONE29/9/202017/6/2026
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to…
ModificadaMedia (5.5)1.3%—Trendmicro Apex ONE29/9/202017/6/2026
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to…
ModificadaMedia (5.5)1.3%—Trendmicro Apex ONE29/9/202017/6/2026
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to…
ModificadaMedia (5.5)1.3%—Trendmicro Apex ONE29/9/202017/6/2026
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to…
ModificadaMedia (5.5)1.3%—Trendmicro Apex ONE29/9/202017/6/2026
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to…
ModificadaAlta (7.8)0.48%—Trendmicro Apex ONE29/9/202017/6/2026
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in…
ModificadaAlta (7.8)0.57%—Trendmicro Officescan29/9/202017/6/2026
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system…
ModificadaAlta (7.5)1.8%—Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+124/9/202017/6/2026
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper…
ModificadaAlta (7.5)1.6%—Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+124/9/202017/6/2026
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files…