VYPR

Password Manager

by Trend Micro

CVEs (16)

  • CVE-2016-3987CriApr 12, 2016
    risk 0.68cvss 9.8epss 0.22

    The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

  • CVE-2021-32462HigJul 8, 2021
    risk 0.58cvss 8.8epss 0.05

    Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected…

  • CVE-2025-52837HigJul 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege…

  • CVE-2022-28394HigMay 27, 2022
    risk 0.51cvss 7.8epss 0.00

    EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was…

  • CVE-2022-30523HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege…

  • CVE-2022-26337HigMar 8, 2022
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the…

  • CVE-2021-32461HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must…

  • CVE-2021-28647HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.

  • CVE-2020-8469HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.

  • CVE-2019-14687HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.02

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

  • CVE-2019-14684HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

  • CVE-2019-15629HigNov 25, 2019
    risk 0.49cvss 7.5epss 0.03

    Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that could be exploited to allow the application to share information to third-party applications on the device.

  • CVE-2025-48443MedJun 17, 2025
    risk 0.44cvss 6.7epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the…

  • CVE-2019-19696MedJan 18, 2020
    risk 0.36cvss 5.5epss 0.00

    A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to…

  • CVE-2019-15625MedJan 18, 2020
    risk 0.36cvss 5.5epss 0.01

    A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.

  • CVE-2024-9203LowSep 26, 2024
    risk 0.16cvss 2.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached…