Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.9% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations. | |
| Analizada | Alta (7.5) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations. | |
| Analizada | Crítica (9.8) | 1.8% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations. | |
| Analizada | Crítica (9) | 0.45% | — | Trendmicro Trend Vision ONE | 2/4/2025 | 17/6/2026 | An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability. | |
| Analizada | Alta (7.2) | 0.27% | — | Trendmicro Trend Vision ONE | 2/4/2025 | 17/6/2026 | A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is… | |
| Analizada | Alta (7.2) | 0.27% | — | Trendmicro Trend Vision ONE | 2/4/2025 | 17/6/2026 | A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no… | |
| Analizada | Alta (7.2) | 0.27% | — | Trendmicro Trend Vision ONE | 2/4/2025 | 17/6/2026 | A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is… | |
| Analizada | Alta (7.2) | 0.27% | — | Trendmicro Trend Vision ONE | 2/4/2025 | 17/6/2026 | A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and… | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 25/3/2025 | 17/6/2026 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attacker must first obtain the… | |
| Analizada | Alta (7.8) | 0.16% | — | Trendmicro Apex ONE | 25/3/2025 | 17/6/2026 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.28% | — | Trendmicro Housecall FOR Home Networks | 22/2/2025 | 17/6/2026 | Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges. | |
| Aplazada | Media (5.4) | 0.10% | — | Txone Networks StellarprotectAITxone Networks StellarenforceAITrendmicro Safe LockAI | 17/2/2025 | 17/6/2026 | Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforce, and Safe Lock allows an attacker to escalate their privileges in the victim’s device. The attacker needs to hijack the DLL file in advance. This issue affects StellarProtect (Legacy Mode): before… | |
| Analizada | Alta (7.3) | 0.14% | — | Trendmicro Deep Security Agent | 31/12/2024 | 17/6/2026 | An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (7.8) | 0.26% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (8.2) | 0.30% | — | Trendmicro ID Security | 31/12/2024 | 17/6/2026 | Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service. | |
| Analizada | Alta (7.8) | 0.47% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (7.8) | 0.33% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52049. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.8) | 1.1% | — | Trendmicro Apex ONE | 31/12/2024 | 17/6/2026 | A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 4.0% | — | Trendmicro Deep Security Agent | 19/11/2024 | 17/6/2026 | A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands… | |
| Analizada | Crítica (9.8) | 2.4% | — | Trendmicro Cloud Edge | 22/10/2024 | 17/6/2026 | An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.75% | — | Trendmicro Deep Security Agent | 22/10/2024 | 17/6/2026 | An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Media (6.5) | 1.2% | — | Trendmicro Deep Discovery Inspector | 22/10/2024 | 17/6/2026 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |