Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.21% | — | Oracle Apex | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 24.2.0 and 24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle APEX… | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 30/9/2026 | A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability. | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 30/9/2026 | A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.. | |
| Analizada | Crítica (9.8) | 3.6% | — | Trendmicro Apex Central | 8/1/2026 | 30/9/2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations. | |
| Aplazada | Crítica (10) | 0.90% | — | Apex Software CO LivebosAI | 27/8/2025 | 26/9/2026 | LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component and allows unauthenticated remote attackers to upload crafted files outside the… | |
| Analizada | Alta (7.8) | 0.23% | — | Nvidia Apex | 13/8/2025 | 17/6/2026 | NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 20% | — | Trendmicro Apex ONE | 5/8/2025 | 17/6/2026 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture. | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa | Trendmicro Apex ONE | 5/8/2025 | 17/6/2026 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | |
| Analizada | Alta (7.1) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the SaaS instance of Apex Central - customers that automatically apply… | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.15% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.92% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations. | |
| Analizada | Alta (7.8) | 0.12% | — | Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security ServicesTrendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain… | |
| Analizada | Crítica (9.8) | 2.1% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | |
| Analizada | Crítica (9.8) | 1.4% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. | |
| Analizada | Crítica (9.8) | 1.9% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations. | |
| Analizada | Alta (7.5) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations. | |
| Analizada | Crítica (9.8) | 1.8% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations. | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 25/3/2025 | 17/6/2026 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attacker must first obtain the… | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 25/3/2025 | 17/6/2026 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.26% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |