Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
225 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 13% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability. | |
| Modificada | Alta (7.5) | 4.6% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 6.2% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 18/3/2020 | 17/6/2026 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication. | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro Officescan | 18/3/2020 | 17/6/2026 | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication. | |
| Modificada | Crítica (9.8) | 5.0% | — | Safescan Ta-8010 FirmwareSafescan Ta-8015 FirmwareSafescan Ta-8020 FirmwareSafescan Ta-8025 Firmware+3 | 13/3/2020 | 17/6/2026 | Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API. | |
| Modificada | Alta (7.5) | 2.1% | — | Safescan Timemoto Tm-616 FirmwareSafescan Ta-8035 FirmwareSafescan Ta-8010 FirmwareSafescan Ta-8015 Firmware+3 | 2/3/2020 | 17/6/2026 | Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API. | |
| Modificada | Media (4.7) | 0.36% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+1 | 20/2/2020 | 17/6/2026 | The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product… | |
| Modificada | Alta (7) | 1.9% | — | Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+4 | 20/2/2020 | 17/6/2026 | Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by… | |
| Modificada | Media (4.9) | 1.2% | — | Trendmicro Apex ONETrendmicro Officescan | 20/12/2019 | 17/6/2026 | A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this vulnerability. | |
| Modificada | Crítica (9.8) | 4.5% | — | Trendmicro Apex ONETrendmicro OfficescanTrendmicro Worry-free Business Security | 28/10/2019 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication. | |
| Analizada | Alta (7.5) | 25% | ⚠ Explotación activa | Trendmicro Officescan | 28/10/2019 | 17/6/2026 | Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is… | |
| Modificada | Media (5.5) | 0.32% | — | Jenkins Codescan | 25/9/2019 | 17/6/2026 | Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (7.8) | 0.60% | — | Trendmicro Officescan | 26/7/2019 | 17/6/2026 | A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system. | |
| Modificada | Alta (7.5) | 2.3% | — | Trendmicro Apex ONETrendmicro Apex ONE AS A ServiceTrendmicro Business SecurityTrendmicro Officescan+1 | 5/4/2019 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console. | |
| Modificada | Alta (7.5) | 1.4% | — | Trendmicro Officescan | 21/12/2018 | 17/6/2026 | A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations. | |
| Modificada | Alta (7.5) | 1.4% | — | Trendmicro Officescan | 21/12/2018 | 17/6/2026 | A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations. | |
| Modificada | Crítica (9.8) | 1.5% | — | Escanav Escan Anti-virus | 20/12/2018 | 17/6/2026 | eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222. | |
| Modificada | Media (4.7) | 2.1% | — | Trendmicro Officescan XG | 30/8/2018 | 17/6/2026 | A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order… | |
| Modificada | Media (5.5) | 0.29% | — | Escanav Escan Internet Security Suite | 13/7/2018 | 17/6/2026 | In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD). | |
| Modificada | Crítica (9.8) | 3.4% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security+2 | 6/7/2018 | 17/6/2026 | A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes. | |
| Modificada | Alta (8.8) | 1.1% | — | Trendmicro Officescan | 12/6/2018 | 17/6/2026 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability. | |
| Modificada | Alta (8.8) | 1.3% | — | Trendmicro Officescan | 12/6/2018 | 17/6/2026 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability. | |
| Modificada | Media (4.4) | 1.4% | 💥 Exploit | Trendmicro Officescan | 12/6/2018 | 17/6/2026 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthorized Change Prevention inoperable on vulnerable installations. An attacker must already have administrator privileges in order to exploit this vulnerability. | |
| Modificada | Media (4.7) | 1.1% | — | Trendmicro Officescan | 8/6/2018 | 17/6/2026 | A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within the processing of IOCTL 0x220004 by the TMWFP driver. An attacker must first obtain the ability to execute… | |
| Modificada | Media (6.3) | 0.36% | — | Trendmicro Officescan | 8/6/2018 | 17/6/2026 | A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220008 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged… |