Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.6%—Trendmicro Password Manager20/8/201917/6/2026
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.
ModificadaAlta (7.8)1.5%—Trendmicro Password Manager20/8/201917/6/2026
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.
ModificadaAlta (7.8)0.60%—Trendmicro Officescan26/7/201917/6/2026
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
ModificadaAlta (8.8)1.5%—Trendmicro Interscan WEB Security Virtual Appliance5/4/201917/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability.
ModificadaAlta (7.5)2.3%—Trendmicro Apex ONETrendmicro Apex ONE AS A ServiceTrendmicro Business SecurityTrendmicro Officescan+15/4/201917/6/2026
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
ModificadaAlta (7.5)2.7%—Trendmicro DR. Safety5/2/201917/6/2026
A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.
ModificadaAlta (7.8)1.8%💥 PoCTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security5/2/201917/6/2026
A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations.
ModificadaAlta (7.5)1.4%—Trendmicro Officescan21/12/201817/6/2026
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.
ModificadaAlta (7.5)1.4%—Trendmicro Officescan21/12/201817/6/2026
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.
ModificadaMedia (6.5)0.95%—Trendmicro DR. Safety21/12/201817/6/2026
An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could allow an attacker to potentially trick a victim into visiting a malicious URL using address bar spoofing on the Private Browser of the app on vulnerable installations.
ModificadaAlta (7.8)0.58%—Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 201923/10/201817/6/2026
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F4E offset user-supplied…
ModificadaAlta (7.8)0.56%—Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 201923/10/201817/6/2026
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F6A offset user-supplied…
ModificadaAlta (7.8)0.56%—Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 201923/10/201817/6/2026
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6eDC offset user-supplied…
ModificadaAlta (7.8)0.56%—Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 201923/10/201817/6/2026
A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target…
ModificadaAlta (7.8)0.54%—Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 201923/10/201817/6/2026
A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system…
ModificadaMedia (5.4)0.81%💥 PoCTrendmicro Deep Discovery Inspector28/9/201817/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
ModificadaMedia (4.7)2.1%—Trendmicro Officescan XG30/8/201817/6/2026
A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order…
ModificadaAlta (7.8)0.47%—Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security30/8/201817/6/2026
An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
ModificadaAlta (7.8)0.41%—Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security30/8/201817/6/2026
A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the…
ModificadaAlta (7.8)0.76%—Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security30/8/201817/6/2026
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the…
ModificadaAlta (7.5)1.1%—Trendmicro Control Manager15/8/201817/6/2026
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS).
ModificadaCrítica (10)2.7%—Trendmicro Control Manager15/8/201817/6/2026
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
ModificadaCrítica (9.8)6.5%—Trendmicro Control Manager15/8/201817/6/2026
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.
ModificadaCrítica (9.8)3.4%💥 PoCTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security+26/7/201817/6/2026
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.
ModificadaAlta (8.8)1.1%—Trendmicro Officescan12/6/201817/6/2026
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability.
Orbitaley — Vulnerabilidades