Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 28 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.38% | — | Proofpoint Protection ServerAI | 11/12/2025 | 1/10/2026 | Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations. | |
| Modificada | Alta (7.5) | 6.3% | — | Trendmicro Smart Protection Server | 25/5/2018 | 17/6/2026 | A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation. | |
| Modificada | Alta (8.8) | 14% | — | Trendmicro Smart Protection Server | 25/5/2018 | 17/6/2026 | A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to… | |
| Modificada | Crítica (9.8) | 6.9% | — | Trendmicro Smart Protection Server | 15/3/2018 | 17/6/2026 | A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations. | |
| Modificada | Crítica (9.8) | 13% | — | Trendmicro Smart Protection Server | 19/1/2018 | 17/6/2026 | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system. | |
| Modificada | Media (6.1) | 3.0% | — | Trendmicro Smart Protection Server | 19/1/2018 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems. | |
| Modificada | Alta (8.1) | 12% | — | Trendmicro Smart Protection Server | 19/1/2018 | 17/6/2026 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system. | |
| Modificada | Crítica (9.8) | 19% | — | Trendmicro Smart Protection Server | 19/1/2018 | 17/6/2026 | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system. | |
| Modificada | Alta (8.8) | 8.2% | — | Trendmicro Smart Protection Server | 19/1/2018 | 17/6/2026 | A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system. | |
| Modificada | Alta (8.8) | 14% | — | Trendmicro Smart Protection Server | 22/9/2017 | 17/6/2026 | Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations. | |
| Modificada | Crítica (9.1) | 3.7% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3)… | |
| Modificada | Alta (7.8) | 0.98% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan horse .war file in the Solr webapps directory. | |
| Modificada | Alta (8.8) | 55% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) spare_Community, (2) spare_AllowGroupIP, or (3) spare_AllowGroupNetmask parameter to… | |
| Modificada | Alta (8.8) | 8.2% | — | Trendmicro Smart Protection Server | 30/1/2017 | 17/6/2026 | ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) host or (2) apikey parameter in a register action, (3) enable parameter in a… | |
| Modificada | Media (6.8) | 0.67% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators… | |
| Modificada | Alta (7.5) | 2.4% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to execute arbitrary commands via unknown vectors, related to a "command injection" issue. | |
| Modificada | Alta (7.5) | 1.3% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | SQL injection vulnerability in an unspecified function in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 1.9% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | Directory traversal vulnerability in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Alta (10) | 11% | — | Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+19 | 11/12/2009 | 16/6/2026 | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)… | |
| Modificada | Media (5) | 3.3% | — | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 13/2/2008 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483. | |
| Modificada | Media (5) | 10% | — | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 20/12/2007 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string. | |
| Modificada | Media (6.4) | 1.4% | — | Proofpoint Protection Server | 31/12/2004 | 16/6/2026 | The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database. |