VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2022-26871CriKEVMar 29, 2022
    risk 0.77cvss 9.8epss 0.20

    An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

  • CVE-2020-8599CriKEVMar 18, 2020
    risk 0.77cvss 9.8epss 0.12

    Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

  • CVE-2025-54948CriKEVAug 5, 2025
    risk 0.75cvss 9.4epss 0.21

    A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

  • CVE-2016-7552CriApr 12, 2017
    risk 0.74cvss 9.8epss 0.93

    On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

  • CVE-2016-7547CriApr 12, 2017
    risk 0.74cvss 9.8epss 0.93

    A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.

  • CVE-2020-8606CriMay 27, 2020
    risk 0.73cvss 9.8epss 0.73

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.

  • CVE-2017-11394CriAug 3, 2017
    risk 0.72cvss 9.8epss 0.67

    Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.

  • CVE-2021-36741HigKEVJul 29, 2021
    risk 0.70cvss 8.8epss 0.05

    An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the…

  • CVE-2020-8468HigKEVMar 18, 2020
    risk 0.70cvss 8.8epss 0.06

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user…

  • CVE-2020-8467HigKEVMar 18, 2020
    risk 0.70cvss 8.8epss 0.11

    A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

  • CVE-2020-8466CriDec 17, 2020
    risk 0.69cvss 9.8epss 0.64

    A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

  • CVE-2020-28578CriNov 18, 2020
    risk 0.69cvss 9.8epss 0.73

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.

  • CVE-2018-6229CriMar 15, 2018
    risk 0.68cvss 9.8epss 0.10

    A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

  • CVE-2018-6228CriMar 15, 2018
    risk 0.68cvss 9.8epss 0.10

    A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

  • CVE-2018-6223CriMar 15, 2018
    risk 0.68cvss 9.8epss 0.10

    A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.

  • CVE-2018-6220CriMar 15, 2018
    risk 0.68cvss 9.8epss 0.10

    An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.

  • CVE-2017-14097CriJan 19, 2018
    risk 0.68cvss 9.8epss 0.13

    An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system.

  • CVE-2017-14094CriJan 19, 2018
    risk 0.68cvss 9.8epss 0.19

    A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.

  • CVE-2017-14078CriSep 22, 2017
    risk 0.68cvss 9.8epss 0.50

    SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

  • CVE-2016-9269CriFeb 21, 2017
    risk 0.68cvss 9.9epss 0.13

    Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as…

  • CVE-2016-3987CriApr 12, 2016
    risk 0.68cvss 9.8epss 0.22

    The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

  • CVE-2020-8605HigMay 27, 2020
    risk 0.67cvss 8.8epss 0.88

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

  • CVE-2017-14089CriOct 6, 2017
    risk 0.67cvss 9.8epss 0.10

    An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.

  • CVE-2017-11385CriAug 2, 2017
    risk 0.67cvss 9.8epss 0.39

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.

  • CVE-2017-11384CriAug 2, 2017
    risk 0.67cvss 9.8epss 0.39

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.

  • CVE-2017-11383CriAug 2, 2017
    risk 0.67cvss 9.8epss 0.39

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.

  • CVE-2017-11389CriAug 2, 2017
    risk 0.66cvss 9.8epss 0.27

    Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

  • CVE-2017-11386CriAug 2, 2017
    risk 0.66cvss 9.8epss 0.24

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.

  • CVE-2023-32521CriJun 26, 2023
    risk 0.65cvss 9.1epss 0.67

    A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.

  • CVE-2020-8598CriMar 18, 2020
    risk 0.65cvss 9.8epss 0.13

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not…

  • CVE-2018-10511CriAug 15, 2018
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.

  • CVE-2017-11393CriAug 3, 2017
    risk 0.65cvss 9.8epss 0.16

    Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.

  • CVE-2017-11391HigAug 3, 2017
    risk 0.65cvss 8.8epss 0.62

    Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly…

  • CVE-2017-6398HigMar 14, 2017
    risk 0.65cvss 8.8epss 0.54

    An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default…

  • CVE-2016-6267HigJan 30, 2017
    risk 0.65cvss 8.8epss 0.55

    SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) spare_Community, (2) spare_AllowGroupIP, or (3)…

  • CVE-2008-2433CriAug 27, 2008
    risk 0.65cvss 9.8epss 0.11

    The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via…

  • CVE-2025-71211CriMay 21, 2026
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note:…

  • CVE-2025-71210CriMay 21, 2026
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via…

  • CVE-2025-69258CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.04

    A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

  • CVE-2025-49217CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.

  • CVE-2025-49216CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

  • CVE-2025-49213CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.10

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.

  • CVE-2025-49212CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.10

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

  • CVE-2025-49220CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.

  • CVE-2025-49219CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

  • CVE-2024-48904CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.02

    An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.

  • CVE-2023-32557CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges.

  • CVE-2023-25143CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.02

    An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.

  • CVE-2023-0587CriFeb 1, 2023
    risk 0.64cvss 9.1epss 0.60

    A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the…

  • CVE-2022-40144CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.

Page 1 of 14