Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 14% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638. | |
| Modificada | Alta (7.5) | 15% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512. | |
| Modificada | Crítica (9.8) | 24% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549. | |
| Modificada | Crítica (9.8) | 38% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545. | |
| Modificada | Crítica (9.8) | 38% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561. | |
| Modificada | Crítica (9.8) | 38% | — | Trendmicro Control Manager | 2/8/2017 | 17/6/2026 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560. | |
| Modificada | Crítica (9.8) | 2.8% | — | Trendmicro Deep Discovery Director | 1/8/2017 | 17/6/2026 | A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console. | |
| Modificada | Crítica (9.8) | 1.5% | — | Trendmicro Deep Discovery Director | 1/8/2017 | 17/6/2026 | Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1. | |
| Modificada | Alta (7.5) | 0.46% | — | Trendmicro Deep Discovery Director | 1/8/2017 | 17/6/2026 | Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8) T117117, (9) T118, (10) T_action_fail, (11)… | |
| Modificada | Alta (7.8) | 0.52% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory. | |
| Modificada | Alta (7.4) | 3.6% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers. | |
| Modificada | Crítica (9.8) | 6.0% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates. | |
| Modificada | Alta (8.8) | 2.3% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to SProtectLinux/scanoption_set.cgi, related to the lack of anti-CSRF… | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Serverprotect | 26/5/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi. | |
| Modificada | Media (6.1) | 0.73% | — | Trendmicro Officescan | 5/5/2017 | 17/6/2026 | Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website. | |
| Modificada | Alta (8.8) | 1.9% | — | Trendmicro Officescan | 3/5/2017 | 17/6/2026 | Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation. | |
| Modificada | Alta (8.8) | 7.0% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter. | |
| Modificada | Alta (8.8) | 6.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 6.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 5.7% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 5.7% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (7.3) | 2.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file. | |
| Modificada | Alta (7.3) | 2.5% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/. | |
| Modificada | Alta (8.8) | 6.1% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |