Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 7.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter. | |
| Modificada | Crítica (9.8) | 5.6% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value. | |
| Modificada | Media (6.1) | 4.3% | 💥 Exploit | Trendmicro Interscan Messaging Security Virtual Appliance | 18/4/2017 | 17/6/2026 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. | |
| Modificada | Media (5.4) | 2.5% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any… | |
| Modificada | Media (6.5) | 4.1% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure… | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and… | |
| Modificada | Media (5.9) | 0.77% | — | Trendmicro Mobile Security | 31/3/2017 | 17/6/2026 | There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398. | |
| Modificada | Media (6.7) | 0.70% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 21/3/2017 | 17/6/2026 | Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent"… | |
| Modificada | Alta (8.8) | 54% | 💥 Exploit | Trendmicro Interscan Messaging Security Virtual Appliance | 14/3/2017 | 17/6/2026 | An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss… | |
| Modificada | Alta (7.8) | 3.9% | — | Trendmicro Endpoint Sensor | 10/3/2017 | 17/6/2026 | Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 21/2/2017 | 17/6/2026 | Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript… | |
| Modificada | Alta (8.8) | 9.0% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 21/2/2017 | 17/6/2026 | Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to change Master Admin's password and/or add new admin… | |
| Modificada | Alta (7.8) | 3.0% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 21/2/2017 | 17/6/2026 | Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup the system configuration and download it onto their local machine.… | |
| Modificada | Crítica (9.9) | 13% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 21/2/2017 | 17/6/2026 | Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. This… | |
| Modificada | Alta (8.8) | 6.1% | — | Trendmicro Virtual Mobile Infrastructure | 30/1/2017 | 17/6/2026 | The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to api/v1/cfg/oauth/save_identify_pfx/. | |
| Modificada | Crítica (9.1) | 3.7% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3)… | |
| Modificada | Alta (7.8) | 0.98% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan horse .war file in the Solr webapps directory. | |
| Modificada | Alta (8.8) | 55% | 💥 Exploit | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) spare_Community, (2) spare_AllowGroupIP, or (3) spare_AllowGroupNetmask parameter to… | |
| Modificada | Alta (8.8) | 8.2% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) host or (2) apikey parameter in a register action, (3) enable parameter in a… | |
| Modificada | Media (6.1) | 1.6% | — | Trendmicro Internet Security | 19/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 3.5% | — | Trendmicro Internet Security | 19/6/2016 | 17/6/2026 | Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/6/2016 | 17/6/2026 | CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (5.3) | 4.2% | — | Trendmicro OfficescanTrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/6/2016 | 17/6/2026 | Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors. |