Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

225 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)13%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security18/3/202017/6/2026
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
ModificadaAlta (7.5)4.6%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security18/3/202017/6/2026
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
AnalizadaAlta (8.8)6.2%⚠ Explotación activaTrendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security18/3/202017/6/2026
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
AnalizadaAlta (8.8)11%⚠ Explotación activaTrendmicro Apex ONETrendmicro Officescan18/3/202017/6/2026
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
ModificadaCrítica (9.8)5.0%—Safescan Ta-8010 FirmwareSafescan Ta-8015 FirmwareSafescan Ta-8020 FirmwareSafescan Ta-8025 Firmware+313/3/202017/6/2026
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
ModificadaAlta (7.5)2.1%—Safescan Timemoto Tm-616 FirmwareSafescan Ta-8035 FirmwareSafescan Ta-8010 FirmwareSafescan Ta-8015 Firmware+32/3/202017/6/2026
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
ModificadaMedia (4.7)0.36%—Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+120/2/202017/6/2026
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product…
ModificadaAlta (7)1.9%—Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+420/2/202017/6/2026
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by…
ModificadaMedia (4.9)1.2%—Trendmicro Apex ONETrendmicro Officescan20/12/201917/6/2026
A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this vulnerability.
ModificadaCrítica (9.8)4.5%—Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security28/10/201917/6/2026
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
AnalizadaAlta (7.5)25%⚠ Explotación activaTrendmicro Officescan28/10/201917/6/2026
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is…
ModificadaMedia (5.5)0.32%—Jenkins Codescan25/9/201917/6/2026
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaAlta (7.8)0.60%—Trendmicro Officescan26/7/201917/6/2026
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
ModificadaAlta (7.5)2.3%—Trendmicro Apex ONETrendmicro Apex ONE AS A ServiceTrendmicro Business SecurityTrendmicro Officescan+15/4/201917/6/2026
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
ModificadaAlta (7.5)1.4%—Trendmicro Officescan21/12/201817/6/2026
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.
ModificadaAlta (7.5)1.4%—Trendmicro Officescan21/12/201817/6/2026
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.
ModificadaCrítica (9.8)1.5%—Escanav Escan Anti-virus20/12/201817/6/2026
eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222.
ModificadaMedia (4.7)2.1%—Trendmicro Officescan XG30/8/201817/6/2026
A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order…
ModificadaMedia (5.5)0.29%—Escanav Escan Internet Security Suite13/7/201817/6/2026
In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).
ModificadaCrítica (9.8)3.4%💥 PoCTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security+26/7/201817/6/2026
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.
ModificadaAlta (8.8)1.1%—Trendmicro Officescan12/6/201817/6/2026
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability.
ModificadaAlta (8.8)1.3%—Trendmicro Officescan12/6/201817/6/2026
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.
ModificadaMedia (4.4)1.4%💥 ExploitTrendmicro Officescan12/6/201817/6/2026
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthorized Change Prevention inoperable on vulnerable installations. An attacker must already have administrator privileges in order to exploit this vulnerability.
ModificadaMedia (4.7)1.1%—Trendmicro Officescan8/6/201817/6/2026
A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within the processing of IOCTL 0x220004 by the TMWFP driver. An attacker must first obtain the ability to execute…
ModificadaMedia (6.3)0.36%—Trendmicro Officescan8/6/201817/6/2026
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220008 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged…
Orbitaley — Vulnerabilidades