Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)14%—Trendmicro Control Manager2/8/201717/6/2026
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
ModificadaAlta (7.5)15%—Trendmicro Control Manager2/8/201717/6/2026
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.
ModificadaCrítica (9.8)24%—Trendmicro Control Manager2/8/201717/6/2026
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.
ModificadaCrítica (9.8)38%—Trendmicro Control Manager2/8/201717/6/2026
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.
ModificadaCrítica (9.8)38%—Trendmicro Control Manager2/8/201717/6/2026
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.
ModificadaCrítica (9.8)38%—Trendmicro Control Manager2/8/201717/6/2026
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.
ModificadaCrítica (9.8)2.8%—Trendmicro Deep Discovery Director1/8/201717/6/2026
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
ModificadaCrítica (9.8)1.5%—Trendmicro Deep Discovery Director1/8/201717/6/2026
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.
ModificadaAlta (7.5)0.46%—Trendmicro Deep Discovery Director1/8/201717/6/2026
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
ModificadaMedia (6.1)2.5%—Trendmicro Serverprotect26/5/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8) T117117, (9) T118, (10) T_action_fail, (11)…
ModificadaAlta (7.8)0.52%—Trendmicro Serverprotect26/5/201717/6/2026
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.
ModificadaAlta (7.4)3.6%—Trendmicro Serverprotect26/5/201717/6/2026
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.
ModificadaCrítica (9.8)6.0%—Trendmicro Serverprotect26/5/201717/6/2026
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.
ModificadaAlta (8.8)2.3%—Trendmicro Serverprotect26/5/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to SProtectLinux/scanoption_set.cgi, related to the lack of anti-CSRF…
ModificadaMedia (6.1)2.5%—Trendmicro Serverprotect26/5/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi.
ModificadaMedia (6.1)0.73%—Trendmicro Officescan5/5/201717/6/2026
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
ModificadaAlta (8.8)1.9%—Trendmicro Officescan3/5/201717/6/2026
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.
ModificadaAlta (8.8)7.0%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.
ModificadaAlta (8.8)6.2%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
ModificadaAlta (8.8)6.2%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
ModificadaAlta (8.8)5.7%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
ModificadaAlta (8.8)5.7%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
ModificadaAlta (7.3)2.2%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
ModificadaAlta (7.3)2.5%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.
ModificadaAlta (8.8)6.1%—Trendmicro Threat Discovery Appliance28/4/201717/6/2026
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.