Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.2% | — | Trendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication. | |
| Modificada | Crítica (9.8) | 13% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability. | |
| Modificada | Alta (7.5) | 4.6% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 6.2% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication. | |
| Modificada | Crítica (9.8) | 4.5% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 28/10/2019 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication. | |
| Modificada | Alta (7.5) | 2.3% | — | Trendmicro Apex ONETrendmicro Apex ONE AS A ServiceTrendmicro Business SecurityTrendmicro Officescan+1 | 5/4/2019 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console. | |
| Modificada | Alta (7) | 1.6% | — | Trendmicro Deep SecurityTrendmicro Endpoint SensorTrendmicro OfficescanTrendmicro Security+1 | 16/2/2018 | 17/6/2026 | A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system. | |
| Modificada | Media (6.1) | 1.6% | — | Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/6/2016 | 17/6/2026 | CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (5.3) | 4.2% | — | Trendmicro OfficescanTrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/6/2016 | 17/6/2026 | Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (5) | 20% | — | Trend Micro OfficescanTrend Micro Worry Free Business Security | 3/10/2008 | 16/6/2026 | Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business… | |
| Modificada | Crítica (9.8) | 11% | — | Trendmicro Client Server Messaging SuiteTrendmicro OfficescanTrendmicro Worry-free Business Security | 27/8/2008 | 16/6/2026 | The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be… |