Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.12% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.12% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.12% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.12% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.12% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.14% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (7.8) | 0.24% | — | Trendmicro Apex ONE | 23/1/2024 | 17/6/2026 | An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.2) | 4.3% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/9/2023 | 17/6/2026 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must… | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.31% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Alta (7.8) | 0.31% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Crítica (9.8) | 1.2% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges. | |
| Modificada | Media (5.5) | 0.29% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Alta (7) | 0.18% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (7) | 0.18% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Media (5.3) | 0.49% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. | |
| Modificada | Media (5.3) | 0.63% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553 | |
| Modificada | Media (5.5) | 0.13% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations. | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Modificada | Media (6.7) | 0.23% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location. Please note: an attacker must… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 0.30% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. |