Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 24/2/2022 | 17/6/2026 | An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow an attacker to flood a temporary log location and consume all disk… | |
| Modificada | Alta (7.1) | 0.40% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 10/1/2022 | 17/6/2026 | A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.27% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 10/1/2022 | 17/6/2026 | A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.46% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 10/1/2022 | 17/6/2026 | A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.64% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 10/1/2022 | 17/6/2026 | A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local privilege escalation on the affected system.… | |
| Modificada | Alta (7.1) | 0.40% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 10/1/2022 | 17/6/2026 | A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.41% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the… | |
| Modificada | Alta (7.8) | 0.38% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.38% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.38% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.38% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.58% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Modificada | Alta (7.5) | 1.1% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 21/10/2021 | 17/6/2026 | A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations. | |
| Modificada | Alta (7.5) | 2.2% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+1 | 16/12/2020 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems. | |
| Modificada | Alta (7.5) | 1.4% | — | Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+5 | 22/10/2020 | 17/6/2026 | In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. | |
| Modificada | Crítica (9.8) | 3.6% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+9 | 22/10/2020 | 17/6/2026 | In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow. | |
| Modificada | Media (6.5) | 2.0% | — | Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+5 | 22/10/2020 | 17/6/2026 | In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service. | |
| Modificada | Alta (7.5) | 3.9% | — | Mozilla Network Security ServicesRedhat Enterprise LinuxFedoraproject FedoraOracle Communications Offline Mediation Controller+2 | 20/10/2020 | 17/6/2026 | A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS… | |
| Modificada | Alta (7.8) | 0.80% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must… | |
| Modificada | Alta (7.1) | 0.63% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code… | |
| Modificada | Alta (7.8) | 0.78% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An… | |
| Modificada | Media (6.7) | 0.55% | — | Trendmicro Antivirus ToolkitTrendmicro Apex ONETrendmicro Deep SecurityTrendmicro Officescan+8 | 5/8/2020 | 17/6/2026 | An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code… | |
| Modificada | Media (6.5) | 1.1% | — | Oracle Security Service | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: SSL API). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service.… | |
| Modificada | Media (5.9) | 1.3% | — | Oracle Security Service | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: None). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this… | |
| Modificada | Media (5.9) | 44% | — | Mozilla Network Security Services | 2/5/2019 | 17/6/2026 | A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41. |