VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2017-8801MedMay 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.

  • CVE-2016-1226MedJun 19, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1224MedJun 19, 2016
    risk 0.40cvss 6.1epss 0.02

    CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

  • CVE-2020-25778MedOct 14, 2020
    risk 0.39cvss 6.0epss 0.01

    Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could supply a kernel pointer and leak several bytes of memory. An attacker must first obtain the ability to execute high-privileged code on the target system in…

  • CVE-2018-6227MedMar 15, 2018
    risk 0.38cvss 5.4epss 0.02

    A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems.

  • CVE-2018-6226MedMar 15, 2018
    risk 0.38cvss 5.4epss 0.02

    Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems.

  • CVE-2017-14085MedOct 6, 2017
    risk 0.38cvss 5.3epss 0.06

    Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.

  • CVE-2017-6340MedApr 5, 2017
    risk 0.38cvss 5.4epss 0.02

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect…

  • CVE-2016-9319MedMar 31, 2017
    risk 0.38cvss 5.9epss 0.01

    There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.

  • CVE-2016-9316MedFeb 21, 2017
    risk 0.38cvss 5.4epss 0.03

    Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least…

  • CVE-2020-27019MedNov 9, 2020
    risk 0.37cvss 5.5epss 0.18

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.

  • CVE-2025-30642MedJun 17, 2025
    risk 0.36cvss 5.5epss 0.00

    A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-32556MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2023-30902MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations.

  • CVE-2022-44648MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.01

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-44647MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.01

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-40140MedSep 19, 2022
    risk 0.36cvss 5.5epss 0.00

    An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-37348MedSep 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is…

  • CVE-2022-37347MedSep 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is…

  • CVE-2022-30702MedJun 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine.

  • CVE-2021-44022MedDec 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-43772MedDec 3, 2021
    risk 0.36cvss 5.5epss 0.00

    Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.

  • CVE-2021-3848MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with higher privileges that…

  • CVE-2021-28646MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations.

  • CVE-2021-25252MedMar 3, 2021
    risk 0.36cvss 5.5epss 0.01

    Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.

  • CVE-2021-25248MedFeb 4, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an…

  • CVE-2021-25226MedJan 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scan engine component. An attacker must first obtain…

  • CVE-2021-25225MedJan 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scheduled scan component. An attacker must first obtain…

  • CVE-2021-25224MedJan 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a manual scan component. An attacker must first obtain…

  • CVE-2020-27018MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.04

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An…

  • CVE-2020-25772MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-25771MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-25770MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24565MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24564MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2019-19696MedJan 18, 2020
    risk 0.36cvss 5.5epss 0.00

    A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to…

  • CVE-2019-15625MedJan 18, 2020
    risk 0.36cvss 5.5epss 0.01

    A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.

  • CVE-2018-6234MedMay 25, 2018
    risk 0.36cvss 5.5epss 0.01

    An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An…

  • CVE-2024-36359MedJun 10, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2023-38627MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-38626MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-38625MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-38624MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-32605MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on…

  • CVE-2023-32604MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on…

  • CVE-2023-32552MedJun 26, 2023
    risk 0.35cvss 5.3epss 0.01

    An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553

  • CVE-2023-32537MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on…

  • CVE-2023-32536MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on…

  • CVE-2021-31521MedJun 17, 2021
    risk 0.35cvss 5.4epss 0.01

    Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.

  • CVE-2021-25245MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.

Page 10 of 14