Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.18% | — | Trendmicro Maximum Security 2022 | 17/6/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Analizada | Alta (7.1) | 0.17% | — | Trendmicro Maximum Security 2022 | 17/6/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method. | |
| Analizada | Crítica (9.8) | 0.55% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | |
| Analizada | Alta (8.8) | 0.33% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.84% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Media (6.6) | 0.22% | — | Trendmicro Password Manager | 17/6/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password… | |
| Analizada | Media (5.5) | 0.17% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.1) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the SaaS instance of Apex Central - customers that automatically apply… | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Media (6.8) | 0.28% | — | Trendmicro Worry-free Business Security Services | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.15% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.92% | — | Trendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations. | |
| Analizada | Alta (7.8) | 0.12% | — | Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security ServicesTrendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain… | |
| Analizada | Crítica (9.8) | 2.1% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | |
| Analizada | Crítica (9.8) | 1.4% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. |