Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.17% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.3) | 0.14% | — | Trendmicro Deep Security Agent | 31/12/2024 | 17/6/2026 | An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.8) | 4.0% | — | Trendmicro Deep Security Agent | 19/11/2024 | 17/6/2026 | A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands… | |
| Analizada | Alta (7.8) | 0.75% | — | Trendmicro Deep Security Agent | 22/10/2024 | 17/6/2026 | An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.53% | — | Trendmicro Deep Security Agent | 10/6/2024 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (7.8) | 0.31% | — | Trendmicro Deep SecurityTrendmicro Deep Security Agent | 23/1/2024 | 17/6/2026 | A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Modificada | Alta (7.8) | 0.24% | — | Trendmicro Deep SecurityTrendmicro Deep Security Agent | 23/1/2024 | 17/6/2026 | An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target… | |
| Modificada | Alta (7.8) | 0.22% | — | Trendmicro Deep Security Agent | 28/9/2022 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Baja (3.3) | 0.43% | — | Trendmicro Deep Security Agent | 28/9/2022 | 17/6/2026 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Baja (3.3) | 0.17% | — | Trendmicro Deep Security Agent | 28/9/2022 | 17/6/2026 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Baja (3.3) | 0.17% | — | Trendmicro Deep Security Agent | 28/9/2022 | 17/6/2026 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 6.4% | — | Trendmicro Deep Security Agent | 20/1/2022 | 17/6/2026 | A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and… | |
| Modificada | Alta (7.5) | 22% | — | Trendmicro Deep Security Agent | 20/1/2022 | 17/6/2026 | A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the… | |
| Modificada | Media (5.5) | 0.62% | — | Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+15 | 3/3/2021 | 17/6/2026 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | |
| Modificada | Alta (7.2) | 4.0% | — | Trendmicro Deep Security ManagerTrendmicro Vulnerability Protection | 27/8/2020 | 17/6/2026 | A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution. | |
| Modificada | Alta (8.1) | 2.6% | — | Trendmicro Deep Security ManagerTrendmicro Vulnerability Protection | 27/8/2020 | 17/6/2026 | If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack.… | |
| Modificada | Alta (8.1) | 2.6% | — | Trendmicro Deep Security ManagerTrendmicro Vulnerability Protection | 27/8/2020 | 17/6/2026 | If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations… | |
| Modificada | Media (6.7) | 0.55% | — | Trendmicro Antivirus ToolkitTrendmicro Apex ONETrendmicro Deep SecurityTrendmicro Officescan+8 | 5/8/2020 | 17/6/2026 | An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code… | |
| Modificada | Alta (8.8) | 2.2% | — | Trendmicro Deep Security AS A Service | 16/12/2019 | 17/6/2026 | A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account. | |
| Modificada | Alta (7.1) | 1.3% | — | Trendmicro Deep Security | 17/10/2019 | 17/6/2026 | Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact. Local OS access is required. Please note that only Windows agents are affected. | |
| Modificada | Alta (7.5) | 1.8% | — | Trendmicro Deep Security | 17/10/2019 | 17/6/2026 | The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability. | |
| Modificada | Media (4.9) | 1.2% | — | Trendmicro Deep Security ManagerTrendmicro Vulnerability Protection | 11/9/2019 | 17/6/2026 | Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM). | |
| Modificada | Alta (7) | 1.6% | — | Trendmicro Deep SecurityTrendmicro Endpoint SensorTrendmicro OfficescanTrendmicro Security+1 | 16/2/2018 | 17/6/2026 | A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system. |