Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (8.8) | 2.9% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 2.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Modificada | Media (6.5) | 2.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Modificada | Alta (8.8) | 2.6% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Alta (8.8) | 2.6% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Alta (8.1) | 3.3% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Crítica (9.1) | 67% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files. | |
| Modificada | Media (5.5) | 0.13% | — | Trendmicro Apex ONE | 26/6/2023 | 17/6/2026 | A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations. | |
| Modificada | Alta (7.8) | 0.37% | — | Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2021Trendmicro Maximum Security 2021Trendmicro Premium Security 2021+8 | 26/6/2023 | 17/6/2026 | Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file is started. | |
| Modificada | Media (6.8) | 0.20% | — | Trendmicro Trend Micro Endpoint Encryption | 22/3/2023 | 17/6/2026 | A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker… | |
| Modificada | Alta (8.8) | 0.99% | — | Trendmicro Txone Stellarone | 22/3/2023 | 17/6/2026 | TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Modificada | Media (6.7) | 0.23% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location. Please note: an attacker must… | |
| Modificada | Alta (7.8) | 0.39% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 0.30% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. | |
| Modificada | Crítica (9.8) | 1.7% | — | Trendmicro Apex ONE | 10/3/2023 | 17/6/2026 | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | |
| Modificada | Crítica (9.1) | 60% | — | Trendmicro Apex ONE | 1/2/2023 | 17/6/2026 | A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e.,… | |
| Modificada | Alta (7) | 0.19% | — | Trendmicro Maximum Security 2022 | 20/1/2023 | 17/6/2026 | A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an arbitrary location, allowing a escalation of… | |
| Modificada | Alta (7.8) | 0.30% | — | Trendmicro Apex ONE | 24/12/2022 | 17/6/2026 | A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an attacker must first obtain the ability to execute… | |
| Modificada | Alta (7.5) | 0.82% | — | Trendmicro Apex ONE | 12/12/2022 | 17/6/2026 | Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been updated to enhance product security. | |
| Modificada | Alta (7.8) | 0.58% | — | Trendmicro Apex ONE | 12/12/2022 | 17/6/2026 | A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (7.8) | 0.35% | — | Trendmicro Apex ONE | 12/12/2022 | 17/6/2026 | An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Alta (7) | 0.17% | — | Trendmicro Apex ONE | 12/12/2022 | 17/6/2026 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… |