Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.59% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Premium Security 2019 | 21/8/2019 | 17/6/2026 | A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service. | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Alta (7.1) | 0.46% | — | Comodo AntivirusComodo FirewallComodo Internet Security | 25/7/2019 | 17/6/2026 | Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through 12.0.0.6870, with the Comodo Container feature, are vulnerable to Sandbox Escape. | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Crítica (9.8) | 3.5% | — | Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+2 | 23/5/2019 | 17/6/2026 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the… | |
| Modificada | Alta (7.8) | 1.5% | — | F-secure Client SecurityF-secure Computer ProtectionF-secure Internet SecurityF-secure PSB Workstation Security+1 | 17/5/2019 | 17/6/2026 | In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a… | |
| Modificada | Alta (7.8) | 1.8% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 5/2/2019 | 17/6/2026 | A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations. | |
| Modificada | Alta (7.8) | 1.1% | — | Eset CompusecEset Deslock+ PROEset Internet SecurityEset Nod32 Antivirus+2 | 7/9/2018 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan… | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability. | |
| Modificada | Alta (7.8) | 0.41% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the… | |
| Modificada | Alta (7.8) | 0.76% | — | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 30/8/2018 | 17/6/2026 | A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the… | |
| Modificada | Alta (7.8) | 1.2% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 25/7/2018 | 17/6/2026 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00… | |
| Modificada | Media (5.5) | 0.29% | — | Escanav Escan Internet Security Suite | 13/7/2018 | 17/6/2026 | In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD). | |
| Modificada | Crítica (9.8) | 3.4% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security+2 | 6/7/2018 | 17/6/2026 | A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes. | |
| Modificada | Alta (7) | 0.29% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.45% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Media (5.5) | 0.66% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability… | |
| Modificada | Alta (7.8) | 0.49% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222060 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.49% | — | Trendmicro Antivirus+Trendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 25/5/2018 | 17/6/2026 | A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x22205C by the tmnciesc.sys driver. An attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.8) | 0.47% | — | Ahnlab V3 Internet Security | 24/4/2018 | 16/6/2026 | Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call. | |
| Modificada | Media (4.4) | 0.53% | — | Mcafee Anti-virus PlusMcafee Endpoint SecurityMcafee Host Intrusion PreventionMcafee Internet Security+2 | 3/4/2018 | 17/6/2026 | Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. | |
| Modificada | Media (5.5) | 0.28% | — | Kingsoft Internet Security 9 Plus | 30/3/2018 | 17/6/2026 | A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030. | |
| Modificada | Media (5.5) | 0.29% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Media (5.5) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations. |