VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2017-14079HigSep 22, 2017
    risk 0.58cvss 8.8epss 0.11

    Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

  • CVE-2017-11395HigSep 22, 2017
    risk 0.58cvss 8.8epss 0.14

    Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.

  • CVE-2017-11388HigAug 2, 2017
    risk 0.58cvss 8.8epss 0.14

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.

  • CVE-2016-8593HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.07

    Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.

  • CVE-2016-8592HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.06

    log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

  • CVE-2016-8591HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.06

    log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

  • CVE-2016-8590HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.06

    log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

  • CVE-2016-8589HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.06

    log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

  • CVE-2016-8586HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.06

    detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

  • CVE-2016-8585HigApr 28, 2017
    risk 0.58cvss 8.8epss 0.07

    admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.

  • CVE-2016-6270HigJan 30, 2017
    risk 0.58cvss 8.8epss 0.06

    The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to…

  • CVE-2016-6266HigJan 30, 2017
    risk 0.58cvss 8.8epss 0.08

    ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) host or (2) apikey parameter in a register…

  • CVE-2026-34926MedKEVMay 21, 2026
    risk 0.57cvss 6.7epss 0.13

    A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the…

  • CVE-2025-49215HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.00

    A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to…

  • CVE-2025-49214HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.01

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2025-49155HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.01

    An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.

  • CVE-2025-49154HigJun 17, 2025
    risk 0.57cvss 8.7epss 0.00

    An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. …

  • CVE-2023-32530HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.02

    Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in…

  • CVE-2023-32529HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.02

    Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in…

  • CVE-2023-32528HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system…

  • CVE-2023-32527HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system…

  • CVE-2023-32524HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-32523HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-25069HigMar 22, 2023
    risk 0.57cvss 8.8epss 0.01

    TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform…

  • CVE-2020-8461HigDec 17, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.

  • CVE-2020-27016HigNov 9, 2020
    risk 0.57cvss 8.8epss 0.02

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker-controlled web…

  • CVE-2019-18191HigDec 16, 2019
    risk 0.57cvss 8.8epss 0.02

    A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account.

  • CVE-2019-9490HigApr 5, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability.

  • CVE-2018-10509HigJun 12, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability.

  • CVE-2018-10508HigJun 12, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.

  • CVE-2018-10352HigMay 23, 2018
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formConfiguration class. Authentication is required to exploit this vulnerability.

  • CVE-2018-10351HigMay 23, 2018
    risk 0.57cvss 8.8epss 0.04

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerability.

  • CVE-2017-14095HigJan 19, 2018
    risk 0.57cvss 8.1epss 0.12

    A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.

  • CVE-2017-14092HigDec 16, 2017
    risk 0.57cvss 8.8epss 0.01

    The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

  • CVE-2017-9033HigMay 26, 2017
    risk 0.57cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to…

  • CVE-2017-5481HigMay 3, 2017
    risk 0.57cvss 8.8epss 0.02

    Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.

  • CVE-2018-6221HigMar 15, 2018
    risk 0.56cvss 8.1epss 0.06

    An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their own.

  • CVE-2017-14084HigOct 6, 2017
    risk 0.56cvss 8.1epss 0.10

    A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.

  • CVE-2024-46902HigOct 22, 2024
    risk 0.55cvss 8.4epss 0.01

    A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute high-privileged code (admin user rights) on…

  • CVE-2024-45335HigOct 22, 2024
    risk 0.55cvss 8.4epss 0.00

    Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a specifically crafted virus to allow itself to bypass and evade a virus scan detection.

  • CVE-2019-9491HigOct 21, 2019
    risk 0.55cvss 7.8epss 0.13

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.

  • CVE-2018-6222HigMar 15, 2018
    risk 0.54cvss 7.8epss 0.01

    Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

  • CVE-2018-3609HigFeb 16, 2018
    risk 0.54cvss 8.1epss 0.21

    A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.

  • CVE-2016-9314HigFeb 21, 2017
    risk 0.54cvss 7.8epss 0.03

    Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup the system configuration…

  • CVE-2023-32522HigJun 26, 2023
    risk 0.53cvss 8.1epss 0.03

    A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2021-31520HigMay 10, 2021
    risk 0.53cvss 8.1epss 0.04

    A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.

  • CVE-2020-15605HigAug 27, 2020
    risk 0.53cvss 8.1epss 0.03

    If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor…

  • CVE-2020-15601HigAug 27, 2020
    risk 0.53cvss 8.1epss 0.03

    If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication…

  • CVE-2024-51503HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.04

    A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain…

  • CVE-2017-14087HigOct 6, 2017
    risk 0.52cvss 7.5epss 0.08

    A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.

Page 3 of 14