Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.9%—Trendmicro Apex Central17/6/202517/6/2026
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.
AnalizadaAlta (7.5)0.30%—Trendmicro Apex Central17/6/202517/6/2026
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations.
AnalizadaCrítica (9.8)1.8%—Trendmicro Apex Central17/6/202517/6/2026
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.
AnalizadaCrítica (9)0.45%—Trendmicro Trend Vision ONE2/4/202517/6/2026
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
AnalizadaAlta (7.2)0.27%—Trendmicro Trend Vision ONE2/4/202517/6/2026
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is…
AnalizadaAlta (7.2)0.27%—Trendmicro Trend Vision ONE2/4/202517/6/2026
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no…
AnalizadaAlta (7.2)0.27%—Trendmicro Trend Vision ONE2/4/202517/6/2026
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is…
AnalizadaAlta (7.2)0.27%—Trendmicro Trend Vision ONE2/4/202517/6/2026
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and…
AnalizadaAlta (7.8)0.16%—Trendmicro Apex ONE25/3/202517/6/2026
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attacker must first obtain the…
AnalizadaAlta (7.8)0.16%—Trendmicro Apex ONE25/3/202517/6/2026
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.28%—Trendmicro Housecall FOR Home Networks22/2/202517/6/2026
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.
AplazadaMedia (5.4)0.10%—Txone Networks StellarprotectAITxone Networks StellarenforceAITrendmicro Safe LockAI17/2/202517/6/2026
Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforce, and Safe Lock allows an attacker to escalate their privileges in the victim’s device. The attacker needs to hijack the DLL file in advance. This issue affects StellarProtect (Legacy Mode): before…
AnalizadaAlta (7.3)0.14%—Trendmicro Deep Security Agent31/12/202417/6/2026
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…
AnalizadaAlta (7.8)0.26%—Trendmicro Apex ONE31/12/202417/6/2026
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AnalizadaAlta (7.8)0.33%—Trendmicro Apex ONE31/12/202417/6/2026
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AnalizadaAlta (7.8)0.33%—Trendmicro Apex ONE31/12/202417/6/2026
An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AnalizadaAlta (8.2)0.30%—Trendmicro ID Security31/12/202417/6/2026
Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.
AnalizadaAlta (7.8)0.47%—Trendmicro Apex ONE31/12/202417/6/2026
A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AnalizadaAlta (7.8)0.33%—Trendmicro Apex ONE31/12/202417/6/2026
A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…
AnalizadaAlta (7.8)0.33%—Trendmicro Apex ONE31/12/202417/6/2026
A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52049. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…
AnalizadaAlta (8.8)1.1%—Trendmicro Apex ONE31/12/202417/6/2026
A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AnalizadaAlta (8.8)4.0%—Trendmicro Deep Security Agent19/11/202417/6/2026
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands…
AnalizadaCrítica (9.8)2.4%—Trendmicro Cloud Edge22/10/202417/6/2026
An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.
AnalizadaAlta (7.8)0.75%—Trendmicro Deep Security Agent22/10/202417/6/2026
An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ModificadaMedia (6.5)1.2%—Trendmicro Deep Discovery Inspector22/10/202417/6/2026
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Orbitaley — Vulnerabilidades