Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.47% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52049. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.8) | 1.1% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.5) | 2.0% | — | Trendmicro Apex ONE | 22/10/2024 | 17/6/2026 | An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Media (6.9) | 0.33% | — | Wikimedia Apex | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2. | |
| Analizada | Alta (8.7) | 0.23% | — | Apexsoftcell LD GEOApexsoftcell LD DP Back Office | 19/9/2024 | 17/6/2026 | This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions… | |
| Analizada | Crítica (9.3) | 0.56% | — | Apexsoftcell LD GEOApexsoftcell LD DP Back Office | 19/9/2024 | 17/6/2026 | This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts. | |
| Analizada | Alta (8.7) | 0.44% | — | Apexsoftcell LD GEOApexsoftcell LD DP Back Office | 19/9/2024 | 17/6/2026 | This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information… | |
| Analizada | Alta (8.7) | 0.47% | — | Apexsoftcell LD GEOApexsoftcell LD DP Back Office | 19/9/2024 | 17/6/2026 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful… | |
| Analizada | Alta (8.7) | 0.44% | — | Apexsoftcell LD GEOApexsoftcell LD DP Back Office | 19/9/2024 | 17/6/2026 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive… | |
| Analizada | Alta (7.8) | 0.63% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Media (5.5) | 0.78% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order… | |
| Modificada | Media (5.5) | 0.61% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to create a denial-of-service condition on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order… | |
| Modificada | Alta (7.8) | 0.89% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7) | 0.40% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (7.8) | 0.35% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Analizada | Alta (7.8) | 0.55% | — | Trendmicro Apex ONE | 10/6/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.1) | 0.55% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Media (6.1) | 2.4% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex Central. Please note: user interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | |
| Modificada | Media (6.1) | 0.94% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52328. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52327. |