Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

225 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)0.36%—Trendmicro Officescan8/6/201817/6/2026
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged…
ModificadaMedia (6.3)0.36%—Trendmicro Officescan8/6/201817/6/2026
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged…
ModificadaAlta (7)1.6%—Trendmicro Deep SecurityTrendmicro Endpoint SensorTrendmicro OfficescanTrendmicro Security+116/2/201817/6/2026
A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.
ModificadaAlta (7.8)0.40%—Escanav Anti-virus25/1/201817/6/2026
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.
ModificadaAlta (7.8)0.40%—Escanav Anti-virus25/1/201817/6/2026
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.
ModificadaAlta (7.8)0.40%—Escanav Anti-virus25/1/201817/6/2026
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.
ModificadaCrítica (9.8)9.8%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.
ModificadaAlta (7)0.67%—Trendmicro OfficescanTrendmicro Officescan XG6/10/201717/6/2026
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute…
ModificadaAlta (7.5)8.3%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
ModificadaAlta (7.5)7.9%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from…
ModificadaMedia (5.3)5.7%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
ModificadaAlta (8.1)10%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.
ModificadaAlta (7.5)5.5%💥 ExploitTrendmicro Officescan6/10/201717/6/2026
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.
ModificadaAlta (7.3)2.2%—Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl31/8/201717/6/2026
An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the…
ModificadaAlta (7.8)2.4%💥 ExploitAutomatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl25/8/201717/6/2026
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2…
ModificadaAlta (7)1.4%💥 ExploitAutomatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl25/8/201717/6/2026
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An…
ModificadaMedia (6.3)8.5%💥 ExploitAutomatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl25/8/201717/6/2026
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker…
ModificadaCrítica (9.8)67%💥 ExploitTrendmicro Officescan3/8/201717/6/2026
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
ModificadaCrítica (9.8)16%—Trendmicro Officescan3/8/201717/6/2026
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.
ModificadaMedia (6.1)0.73%—Trendmicro Officescan5/5/201717/6/2026
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
ModificadaAlta (8.8)1.9%—Trendmicro Officescan3/5/201717/6/2026
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.
ModificadaCrítica (9.8)3.5%—Emerson Liebert Sitescan WEB13/2/201717/6/2026
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.
ModificadaMedia (5.3)4.2%—Trendmicro OfficescanTrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services19/6/201617/6/2026
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (9.3)5.7%—Panda Activescan11/2/201016/6/2026
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute…
ModificadaMedia (5)1.7%—Trendmicro Officescan10/2/201016/6/2026
Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029, allows attackers to cause a denial of service (crash or OfficeScan hang) via unspecified vectors. NOTE: it is likely that this issue also affects tmufeng.dll before…
Orbitaley — Vulnerabilidades