Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 1.5% | ⚠ Explotación activa | Trendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security | 29/7/2021 | 17/6/2026 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.8) | 5.0% | ⚠ Explotación activa | Trendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security | 29/7/2021 | 17/6/2026 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management… | |
| Modificada | Alta (7.8) | 0.36% | — | Trendmicro Apex ONETrendmicro Worry-free Business Security | 20/7/2021 | 17/6/2026 | An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on affected installations. Please note: an… | |
| Modificada | Media (5.5) | 0.62% | — | Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+15 | 3/3/2021 | 17/6/2026 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | |
| Modificada | Alta (7.8) | 0.43% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Media (5.5) | 0.89% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to… | |
| Modificada | Media (6.5) | 1.7% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries. | |
| Modificada | Media (5.3) | 1.5% | — | Trendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton. | |
| Modificada | Media (5.3) | 1.5% | — | Trendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of configuration informaiton. | |
| Modificada | Media (5.3) | 2.2% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information. | |
| Modificada | Media (5.3) | 2.2% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information. | |
| Modificada | Media (5.3) | 1.9% | — | Trendmicro Apex ONETrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port. | |
| Modificada | Media (5.3) | 1.9% | — | Trendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file. | |
| Modificada | Media (5.3) | 2.2% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file. | |
| Modificada | Media (5.3) | 2.1% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 4/2/2021 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history. | |
| Modificada | Alta (7.5) | 2.8% | — | Trendmicro Worry-free Business Security | 18/11/2020 | 17/6/2026 | A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console. | |
| Modificada | Alta (7.8) | 0.80% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must… | |
| Modificada | Alta (7.1) | 0.63% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code… | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro Worry-free Business Security | 1/9/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.78% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 1/9/2020 | 17/6/2026 | A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An… |