Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.2) | 4.3% | ⚠ Explotación activa | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 19/9/2023 | 17/6/2026 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must… | |
| Modificada | Alta (7.5) | 1.5% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product. | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.23% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to… | |
| Modificada | Alta (7.8) | 0.31% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Alta (7.8) | 0.31% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this… | |
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this… | |
| Modificada | Crítica (9.8) | 1.2% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges. | |
| Modificada | Media (5.5) | 0.29% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Alta (7) | 0.18% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (7) | 0.18% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Media (5.3) | 0.49% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. | |
| Modificada | Media (5.3) | 0.63% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553 | |
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this… | |
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this… | |
| Modificada | Media (6.1) | 1.9% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32534. | |
| Modificada | Media (6.1) | 0.68% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535. | |
| Modificada | Media (6.1) | 1.9% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535. | |
| Modificada | Media (6.1) | 1.9% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535. | |
| Modificada | Media (6.1) | 1.9% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535. | |
| Modificada | Alta (8.8) | 2.4% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in order to exploit these vulnerabilities. This… | |
| Modificada | Alta (8.8) | 2.2% | — | Trendmicro Apex Central | 26/6/2023 | 17/6/2026 | Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in order to exploit these vulnerabilities. This… |