Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 392 respecto a la semana anterior
Críticas / altas1301▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method. | |
| Analizada | Crítica (9.8) | 0.55% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | |
| Analizada | Alta (8.8) | 0.33% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 0.84% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method. | |
| Analizada | Crítica (9.8) | 13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Trend Micro Endpoint Encryption | 17/6/2025 | 17/6/2026 | A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability. | |
| Modificada | Media (6.8) | 0.20% | — | Trendmicro Trend Micro Endpoint Encryption | 22/3/2023 | 17/6/2026 | A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker… |