VYPR

Vendor CVEs

Trellix

All CVEs

55 total · sorted by risk
  • CVE-2024-4843MedMay 16, 2024
    risk 0.28cvss 4.3epss 0.00

    ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.

  • CVE-2023-6070MedNov 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts…

  • CVE-2024-4176MedJun 13, 2024
    risk 0.27cvss 4.1epss 0.00

    An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted…

  • CVE-2026-12588MedJul 14, 2026
    risk 0.00cvss epss 0.00

    An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.

  • CVE-2025-7958HigJun 26, 2026
    risk 0.00cvss epss 0.00

    A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.

Page 2 of 2