VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2025-48443MedJun 17, 2025
    risk 0.44cvss 6.7epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the…

  • CVE-2025-49487MedJun 17, 2025
    risk 0.44cvss 6.8epss 0.00

    An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to…

  • CVE-2025-49158MedJun 17, 2025
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2024-55955MedDec 31, 2024
    risk 0.44cvss 6.7epss 0.00

    An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2023-28005MedMar 22, 2023
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to…

  • CVE-2023-25147MedMar 10, 2023
    risk 0.44cvss 6.7epss 0.00

    An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain…

  • CVE-2022-41748MedOct 10, 2022
    risk 0.44cvss 6.7epss 0.00

    A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an…

  • CVE-2020-28575MedDec 1, 2020
    risk 0.44cvss 6.7epss 0.01

    A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute high-privileged code on the target in order to…

  • CVE-2020-8607MedAug 5, 2020
    risk 0.44cvss 6.7epss 0.01

    An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a…

  • CVE-2019-19697MedJan 18, 2020
    risk 0.44cvss 6.7epss 0.01

    An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must…

  • CVE-2017-5565MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any…

  • CVE-2017-14096MedJan 19, 2018
    risk 0.43cvss 6.1epss 0.03

    A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.

  • CVE-2017-7896MedApr 18, 2017
    risk 0.43cvss 6.1epss 0.04

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.

  • CVE-2016-1225MedJun 19, 2016
    risk 0.43cvss 6.5epss 0.03

    Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2025-30679MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations.

  • CVE-2025-30678MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations.

  • CVE-2024-53647MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.00

    Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.

  • CVE-2024-46903MedOct 22, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2023-32526MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-32525MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2022-26319MedMar 8, 2022
    risk 0.42cvss 6.5epss 0.00

    An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the…

  • CVE-2021-32459MedMay 27, 2021
    risk 0.42cvss 6.5epss 0.01

    Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the…

  • CVE-2021-25246MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.02

    An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make…

  • CVE-2020-27014MedOct 30, 2020
    risk 0.42cvss 6.4epss 0.00

    Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute…

  • CVE-2018-18330MedDec 21, 2018
    risk 0.42cvss 6.5epss 0.01

    An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could allow an attacker to potentially trick a victim into visiting a malicious URL using address bar spoofing on the Private Browser of the app on vulnerable…

  • CVE-2018-10353MedMay 23, 2018
    risk 0.42cvss 6.5epss 0.01

    A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive information on vulnerable installations due to a flaw in the formChangePass class. Authentication is required to exploit this…

  • CVE-2018-3600MedFeb 9, 2018
    risk 0.42cvss 6.5epss 0.02

    A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.

  • CVE-2020-25775MedSep 29, 2020
    risk 0.41cvss 6.3epss 0.00

    The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.

  • CVE-2018-10505MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.00

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220008 in the TMWFP driver. An attacker must first obtain…

  • CVE-2018-10359MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.00

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An attacker must first obtain…

  • CVE-2018-10358MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.00

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain…

  • CVE-2024-36306MedJun 10, 2024
    risk 0.40cvss 6.1epss 0.01

    A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to create a denial-of-service condition on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-52330MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex Central. Please note: user interaction is required to exploit this vulnerability in that the target must…

  • CVE-2023-52329MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.01

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to…

  • CVE-2023-52328MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to…

  • CVE-2023-52327MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to…

  • CVE-2023-52326MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to…

  • CVE-2023-41178MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to,…

  • CVE-2023-41177MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.01

    Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to,…

  • CVE-2023-41176MedJan 23, 2024
    risk 0.40cvss 6.1epss 0.02

    Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to,…

  • CVE-2023-32535MedJun 26, 2023
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32534.

  • CVE-2023-32534MedJun 26, 2023
    risk 0.40cvss 6.1epss 0.01

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.

  • CVE-2023-32533MedJun 26, 2023
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.

  • CVE-2023-32532MedJun 26, 2023
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.

  • CVE-2023-32531MedJun 26, 2023
    risk 0.40cvss 6.1epss 0.02

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535.

  • CVE-2020-8603MedMay 27, 2020
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2019-19692MedDec 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected.

  • CVE-2017-14093MedDec 16, 2017
    risk 0.40cvss 6.1epss 0.01

    The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.

  • CVE-2017-9037MedMay 26, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8) T117117,…

  • CVE-2017-9032MedMay 26, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi.

Page 9 of 14