VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2022-25330CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.05

    Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.

  • CVE-2022-25329CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…

  • CVE-2021-36745CriSep 29, 2021
    risk 0.64cvss 9.8epss 0.09

    A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected…

  • CVE-2020-8465CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.

  • CVE-2020-8600CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.04

    Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.

  • CVE-2019-19690CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.01

    Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.

  • CVE-2019-18190CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.03

    Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

  • CVE-2019-18189CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.05

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not…

  • CVE-2018-10510CriAug 15, 2018
    risk 0.64cvss 9.8epss 0.06

    A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.

  • CVE-2018-3608CriJul 6, 2018
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected…

  • CVE-2018-6231CriMar 15, 2018
    risk 0.64cvss 9.8epss 0.07

    A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.

  • CVE-2018-3601CriFeb 9, 2018
    risk 0.64cvss 9.8epss 0.04

    A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.

  • CVE-2017-14080CriSep 22, 2017
    risk 0.64cvss 9.8epss 0.03

    Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.

  • CVE-2017-11381CriAug 1, 2017
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.

  • CVE-2017-11380CriAug 1, 2017
    risk 0.64cvss 9.8epss 0.01

    Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.

  • CVE-2017-9034CriMay 26, 2017
    risk 0.64cvss 9.8epss 0.06

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.

  • CVE-2016-8584CriApr 28, 2017
    risk 0.64cvss 9.8epss 0.06

    Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.

  • CVE-2016-4351CriMay 5, 2016
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2021-36742HigKEVJul 29, 2021
    risk 0.63cvss 7.8epss 0.01

    A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2020-24557HigKEVSep 1, 2020
    risk 0.63cvss 7.8epss 0.03

    A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An…

  • CVE-2019-18187HigKEVOct 28, 2019
    risk 0.63cvss 7.5epss 0.25

    Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution…

  • CVE-2018-10357HigMay 23, 2018
    risk 0.63cvss 8.8epss 0.73

    A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.

  • CVE-2018-3604HigFeb 9, 2018
    risk 0.63cvss 8.8epss 0.68

    GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

  • CVE-2017-11392HigAug 3, 2017
    risk 0.63cvss 8.8epss 0.34

    Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly…

  • CVE-2025-54987CriAug 5, 2025
    risk 0.62cvss 9.4epss 0.17

    A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different…

  • CVE-2020-28579HigNov 18, 2020
    risk 0.61cvss 8.8epss 0.51

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.

  • CVE-2018-3606HigFeb 9, 2018
    risk 0.61cvss 8.8epss 0.49

    XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

  • CVE-2017-11398HigJan 19, 2018
    risk 0.61cvss 8.8epss 0.08

    A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.

  • CVE-2016-9315HigFeb 21, 2017
    risk 0.61cvss 8.8epss 0.09

    Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to change Master…

  • CVE-2020-24561CriSep 15, 2020
    risk 0.60cvss 9.1epss 0.05

    A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.

  • CVE-2018-6224HigMar 15, 2018
    risk 0.60cvss 8.8epss 0.02

    A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain.

  • CVE-2023-41179HigKEVSep 19, 2023
    risk 0.59cvss 7.2epss 0.05

    A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected…

  • CVE-2022-41746CriOct 10, 2022
    risk 0.59cvss 9.1epss 0.01

    A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex…

  • CVE-2022-40980CriSep 19, 2022
    risk 0.59cvss 9.1epss 0.01

    A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2.

  • CVE-2022-40139HigKEVSep 19, 2022
    risk 0.59cvss 7.2epss 0.03

    Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to…

  • CVE-2020-8604HigMay 27, 2020
    risk 0.59cvss 7.5epss 0.90

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

  • CVE-2018-3605HigFeb 9, 2018
    risk 0.59cvss 8.8epss 0.20

    TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

  • CVE-2017-14090CriDec 16, 2017
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

  • CVE-2017-14081HigSep 22, 2017
    risk 0.59cvss 8.8epss 0.17

    Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

  • CVE-2016-6269CriJan 30, 2017
    risk 0.59cvss 9.1epss 0.04

    Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1)…

  • CVE-2023-52324HigJan 23, 2024
    risk 0.58cvss 8.8epss 0.04

    An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when…

  • CVE-2021-32465HigAug 4, 2021
    risk 0.58cvss 8.8epss 0.04

    An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2021-32462HigJul 8, 2021
    risk 0.58cvss 8.8epss 0.05

    Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected…

  • CVE-2020-27694HigNov 9, 2020
    risk 0.58cvss 8.8epss 0.07

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.

  • CVE-2018-10350HigMay 25, 2018
    risk 0.58cvss 8.8epss 0.15

    A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. …

  • CVE-2018-10356HigMay 23, 2018
    risk 0.58cvss 8.8epss 0.10

    A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is required to exploit this…

  • CVE-2018-10354HigMay 23, 2018
    risk 0.58cvss 8.8epss 0.13

    A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this…

  • CVE-2018-3607HigFeb 9, 2018
    risk 0.58cvss 8.8epss 0.14

    XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

  • CVE-2018-3603HigFeb 9, 2018
    risk 0.58cvss 8.8epss 0.08

    A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

  • CVE-2018-3602HigFeb 9, 2018
    risk 0.58cvss 8.8epss 0.08

    An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

Page 2 of 14