Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

225 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.31%—Escanav Escan Anti-virus16/8/202317/6/2026
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned permissions. The attack needs to be approached locally. The exploit has been disclosed to the public…
ModificadaMedia (4.3)0.39%—Websitescanner Remove Schema1/7/202317/6/2026
The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted…
ModificadaMedia (5.4)0.81%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.
ModificadaMedia (5.4)0.81%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.
ModificadaMedia (5.4)0.81%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.
ModificadaMedia (5.4)0.76%💥 PoCEscanav Escan Management Console27/6/202317/6/2026
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
ModificadaMedia (6.1)0.81%💥 PoCEscanav Escan Management Console2/6/202317/6/2026
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
ModificadaMedia (6.1)0.84%💥 PoCEscanav Escan Management Console31/5/202317/6/2026
Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.
ModificadaCrítica (9.8)1.2%💥 PoCEscanav Escan Management Console31/5/202317/6/2026
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
ModificadaMedia (5.5)0.33%—Escanav Escan Anti-virus24/5/202317/6/2026
A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The…
ModificadaCrítica (9)4.5%💥 ExploitEscanav Escan Management Console17/5/202317/6/2026
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
ModificadaAlta (7.2)4.3%💥 ExploitEscanav Escan Management Console17/5/202317/6/2026
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.
ModificadaAlta (8.8)2.4%—Escanav Escan Anti-virus1/4/202217/6/2026
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.
ModificadaAlta (8.8)4.3%—Trendmicro Apex ONETrendmicro Officescan4/8/202117/6/2026
An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…
ModificadaAlta (7.8)0.59%—Trendmicro Apex ONETrendmicro Officescan4/8/202117/6/2026
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code…
AnalizadaAlta (7.8)1.5%⚠ Explotación activaTrendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security29/7/202117/6/2026
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…
AnalizadaAlta (8.8)5.0%⚠ Explotación activaTrendmicro OfficescanTrendmicro Officescan Business SecurityTrendmicro Apex ONETrendmicro Worry-free Business Security29/7/202117/6/2026
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management…
ModificadaMedia (5.5)0.42%—Trendmicro Apex ONETrendmicro Officescan13/4/202117/6/2026
An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations.
ModificadaAlta (7.8)0.51%—Trendmicro Apex ONETrendmicro Officescan13/4/202117/6/2026
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (7.8)1.9%💥 PoCTrendmicro Apex ONETrendmicro Officescan13/4/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…
ModificadaAlta (7.8)0.51%—Trendmicro Apex ONETrendmicro Officescan13/4/202117/6/2026
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
ModificadaMedia (5.5)0.62%—Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+153/3/202117/6/2026
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ModificadaAlta (7.8)0.43%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…
ModificadaMedia (5.5)0.89%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to…
ModificadaMedia (6.5)1.7%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security4/2/202117/6/2026
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.
Orbitaley — Vulnerabilidades