Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 1.0% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 26/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying… | |
| Aplazada | Media (6.2) | 0.16% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code… | |
| Aplazada | Media (5.3) | 0.36% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS… | |
| Aplazada | Media (6.5) | 0.21% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide… | |
| Analizada | Media (5.5) | 0.15% | — | Oracle Apex | 21/7/2026 | 5/8/2026 | Vulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX. Successful attacks of this vulnerability can… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Apex | 21/7/2026 | 6/8/2026 | Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a… | |
| Aplazada | Alta (8.8) | 2.4% | — | Pensar ApexAI | 27/5/2026 | 17/6/2026 | @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec().… | |
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Media (6.7) | 0.54% | ⚠ Explotación activa | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential… | |
| Analizada | Alta (7.8) | 0.29% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.32% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7) | 0.30% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.36% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.54% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 3.8% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerability carries a technical… | |
| Analizada | Crítica (9.8) | 3.8% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through… | |
| Aplazada | Media (5.5) | 0.59% | — | Fujian Apex LivebosAI | 1/5/2026 | 17/6/2026 | A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component Endpoint. Such manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Pendiente de análisis | Crítica (9) | 0.58% | — | Nvidia ApexAIPytorchAI | 24/3/2026 | 17/6/2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of… |