Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 7.0% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter. | |
| Modificada | Alta (8.8) | 6.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 6.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 5.7% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 5.7% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (7.3) | 2.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file. | |
| Modificada | Alta (7.3) | 2.5% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/. | |
| Modificada | Alta (8.8) | 6.1% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 7.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter. | |
| Modificada | Crítica (9.8) | 5.6% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. |