Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.0%—Trendmicro Mobile Security26/6/202317/6/2026
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
ModificadaAlta (8.8)2.6%—Trendmicro Mobile Security26/6/202317/6/2026
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (8.8)2.6%—Trendmicro Mobile Security26/6/202317/6/2026
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (8.1)3.3%—Trendmicro Mobile Security26/6/202317/6/2026
A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ModificadaCrítica (9.1)67%—Trendmicro Mobile Security26/6/202317/6/2026
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.
ModificadaAlta (7.5)1.3%—Opensecurity Mobile Security Framework18/10/202217/6/2026
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.
ModificadaCrítica (9.1)1.2%—Trendmicro Mobile Security19/9/202217/6/2026
A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2.
ModificadaAlta (7.5)1.4%—Eset Cyber SecurityEset Internet SecurityEset Mobile SecurityEset Nod32 Antivirus+26/3/202017/6/2026
ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV…
ModificadaCrítica (9.8)1.7%—Eset Cyber SecurityEset Mobile SecurityEset Nod32 AntivirusEset Smart Security+15/3/202017/6/2026
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32…
ModificadaAlta (7)1.9%—Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+420/2/202017/6/2026
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by…
ModificadaMedia (5.5)1.2%—Eset Cyber SecurityEset Internet SecurityEset Mobile SecurityEset Nod32 Antivirus+218/2/202017/6/2026
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV…
ModificadaMedia (5.3)1.4%—Symantec Norton Mobile Security8/1/202017/6/2026
A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.
ModificadaMedia (5.5)0.46%—Symantec Norton Mobile Security8/1/202017/6/2026
An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.
ModificadaBaja (3.7)1.3%—Symantec Norton Mobile Security8/1/202017/6/2026
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.
ModificadaCrítica (9.8)1.5%—Trendmicro Mobile Security18/12/201917/6/2026
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
ModificadaAlta (7.5)3.9%—Trendmicro Mobile Security19/1/201817/6/2026
An uninitialized pointer information disclosure vulnerability in Trend Micro Mobile Security (Enterprise) versions 9.7 and below could allow an unauthenticated remote attacker to disclosure sensitive information on a vulnerable system.
ModificadaAlta (8.8)17%—Trendmicro Mobile Security22/9/201717/6/2026
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
ModificadaCrítica (9.8)3.0%—Trendmicro Mobile Security22/9/201717/6/2026
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.
ModificadaAlta (8.8)11%—Trendmicro Mobile Security22/9/201717/6/2026
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
ModificadaCrítica (9.8)50%—Trendmicro Mobile Security22/9/201717/6/2026
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
ModificadaAlta (7.5)1.1%—Avira Mobile Security15/6/201717/6/2026
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.
ModificadaMedia (5.9)0.66%—Watchguard Panda Mobile Security5/5/201717/6/2026
Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
ModificadaMedia (5.9)0.77%—Trendmicro Mobile Security31/3/201717/6/2026
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
ModificadaAlta (7.4)0.93%—Trend Micro Mobile Security23/5/201617/6/2026
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.34%—NQ Mobile Security & Antivirus9/9/201417/6/2026
The NQ Mobile Security & Antivirus (aka com.nqmobile.antivirus20) application 7.2.16.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.