trendmicro records
575 published records for vendor trendmicro.
Researcher profile
- Entered KEV
- 12 · 2.1%
- Weaponized
- 24 · 4.2%
- Pre-auth RCE
- 52
- With a fix record
- 31.3%
- Median publish → KEV
- 97 days
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')41
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')39
- CWE-269 Improper Privilege Management31
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')28
- CWE-427 Uncontrolled Search Path Element28
- CWE-346 Origin Validation Error24
The weakness classes this vendor ships most often: where to look.
CWEAll records
575 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2025-54948Weaponized | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious trendmicro · apex one · CWE-78 | Critical9.8 | KEV | 22.0% | Aug 5, 2025 |
75This week | CVE-2022-26871Weaponized | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary filtrendmicro · apex central · CWE-345 | Critical9.8 | KEV | 19.5% | Mar 29, 2022 |
73This week | CVE-2020-8599Weaponized | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dattrendmicro · apex one | Critical9.8 | KEV | 11.9% | Mar 17, 2020 |
68This week | CVE-2019-18187Weaponized | Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extractrendmicro · officescan · CWE-22 | High7.5 | KEV | 25.1% | Oct 28, 2019 |
68This week | CVE-2020-8467Weaponized | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to etrendmicro · apex one | High8.8 | KEV | 10.9% | Mar 17, 2020 |
67This week | CVE-2016-7552Weaponized | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenttrendmicro · threat discovery appliance · CWE-22 | Critical9.8 | — | 93.2% | Apr 12, 2017 |
67This week | CVE-2016-7547Weaponized | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.ctrendmicro · threat discovery appliance · CWE-361 | Critical9.8 | — | 92.7% | Apr 12, 2017 |
67This week | CVE-2020-8468Weaponized | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | High8.8 | KEV | 6.2% | Mar 17, 2020 |
66This week | CVE-2021-36741Weaponized | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1trendmicro · officescan · CWE-434 | High8.8 | KEV | 5.0% | Jul 29, 2021 |
62This week | CVE-2020-24557Weaponized | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate amicrosoft · windows | High7.8 | KEV | 2.7% | Sep 1, 2020 |
61This week | CVE-2020-8605Weaponized | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affectedtrendmicro · interscan web security virtual appliance · CWE-78 | High8.8 | — | 87.8% | May 27, 2020 |
61This week | CVE-2020-28578No exploit | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sptrendmicro · interscan web security virtual appliance · CWE-787 | Critical9.8 | — | 73.0% | Nov 18, 2020 |
61This week | CVE-2020-8606Weaponized | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected trendmicro · interscan web security virtual appliance · CWE-287 | Critical9.8 | — | 72.7% | May 27, 2020 |
61This week | CVE-2021-36742Weaponized | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.trendmicro · officescan · CWE-20 | High7.8 | KEV | 1.5% | Jul 29, 2021 |
59Plan | CVE-2017-11394Weaponized | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerabtrendmicro · officescan · CWE-20 | Critical9.8 | — | 66.8% | Aug 3, 2017 |
59Plan | CVE-2023-41179Weaponized | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security antrendmicro · apex one · CWE-94 | High7.2 | KEV | 4.3% | Sep 19, 2023 |
59Plan | CVE-2022-40139Weaponized | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients trendmicro · apex one | High7.2 | KEV | 3.3% | Sep 19, 2022 |
58Plan | CVE-2020-8466No exploit | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing methodtrendmicro · interscan web security virtual appliance · CWE-78 | Critical9.8 | — | 64.1% | Dec 17, 2020 |
57Plan | CVE-2020-8604Weaponized | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on trendmicro · interscan web security virtual appliance · CWE-22 | High7.5 | — | 89.8% | May 27, 2020 |
56Plan | CVE-2023-32521No exploit | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated rtrendmicro · mobile security · CWE-22 | Critical9.1 | — | 66.8% | Jun 26, 2023 |
56Plan | CVE-2026-34926Weaponized | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tabletrendmicro · apex one · CWE-23 | Medium6.7 | KEV | 0.5% | May 21, 2026 |
55Plan | CVE-2018-3604No exploit | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to trendmicro · control manager · CWE-89 | High8.8 | — | 67.8% | Feb 9, 2018 |
54Plan | CVE-2018-10357No exploit | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code trendmicro · endpoint application control · CWE-22 | High8.8 | — | 64.7% | May 23, 2018 |
54Plan | CVE-2017-11391Weaponized | Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute artrendmicro · interscan messaging security virtual appliance · CWE-77 | High8.8 | — | 61.8% | Aug 3, 2017 |
54Plan | CVE-2023-0587No exploit | A file upload vulnerability in exists in Trend Micro Apex One server build 11110.trendmicro · apex one · CWE-434 | Critical9.1 | — | 59.6% | Jan 31, 2023 |
- CVE-2025-5494876This week
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious
CriticalCVSS 9.8KEVWeaponizedEPSS 22%trendmicro · apex oneAug 5, 2025
- CVE-2022-2687175This week
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary fil
CriticalCVSS 9.8KEVWeaponizedEPSS 19%trendmicro · apex centralMar 29, 2022
- CVE-2020-859973This week
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dat
CriticalCVSS 9.8KEVWeaponizedEPSS 12%trendmicro · apex oneMar 17, 2020
- CVE-2019-1818768This week
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extrac
HighCVSS 7.5KEVWeaponizedEPSS 25%trendmicro · officescanOct 28, 2019
- CVE-2020-846768This week
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to e
HighCVSS 8.8KEVWeaponizedEPSS 11%trendmicro · apex oneMar 17, 2020
- CVE-2016-755267This week
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthent
CriticalCVSS 9.8WeaponizedEPSS 93%trendmicro · threat discovery applianceApr 12, 2017
- CVE-2016-754767This week
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c
CriticalCVSS 9.8WeaponizedEPSS 93%trendmicro · threat discovery applianceApr 12, 2017
- CVE-2020-846867This week
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
HighCVSS 8.8KEVWeaponizedEPSS 6%trendmicro · apex oneMar 17, 2020
- CVE-2021-3674166This week
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1
HighCVSS 8.8KEVWeaponizedEPSS 5%trendmicro · officescanJul 29, 2021
- CVE-2020-2455762This week
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a
HighCVSS 7.8KEVWeaponizedEPSS 3%microsoft · windowsSep 1, 2020
- CVE-2020-860561This week
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected
HighCVSS 8.8WeaponizedEPSS 88%trendmicro · interscan web security virtual applianceMay 27, 2020
- CVE-2020-2857861This week
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sp
CriticalCVSS 9.8No exploitEPSS 73%trendmicro · interscan web security virtual applianceNov 18, 2020
- CVE-2020-860661This week
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected
CriticalCVSS 9.8WeaponizedEPSS 73%trendmicro · interscan web security virtual applianceMay 27, 2020
- CVE-2021-3674261This week
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.
HighCVSS 7.8KEVWeaponizedEPSS 1%trendmicro · officescanJul 29, 2021
- CVE-2017-1139459Plan
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerab
CriticalCVSS 9.8WeaponizedEPSS 67%trendmicro · officescanAug 3, 2017
- CVE-2023-4117959Plan
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security an
HighCVSS 7.2KEVWeaponizedEPSS 4%trendmicro · apex oneSep 19, 2023
- CVE-2022-4013959Plan
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients
HighCVSS 7.2KEVWeaponizedEPSS 3%trendmicro · apex oneSep 19, 2022
- CVE-2020-846658Plan
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method
CriticalCVSS 9.8No exploitEPSS 64%trendmicro · interscan web security virtual applianceDec 17, 2020
- CVE-2020-860457Plan
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on
HighCVSS 7.5WeaponizedEPSS 90%trendmicro · interscan web security virtual applianceMay 27, 2020
- CVE-2023-3252156Plan
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated r
CriticalCVSS 9.1No exploitEPSS 67%trendmicro · mobile securityJun 26, 2023
- CVE-2026-3492656Plan
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table
MediumCVSS 6.7KEVWeaponizedEPSS 1%trendmicro · apex oneMay 21, 2026
- CVE-2018-360455Plan
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to
HighCVSS 8.8No exploitEPSS 68%trendmicro · control managerFeb 9, 2018
- CVE-2018-1035754Plan
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code
HighCVSS 8.8No exploitEPSS 65%trendmicro · endpoint application controlMay 23, 2018
- CVE-2017-1139154Plan
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute ar
HighCVSS 8.8WeaponizedEPSS 62%trendmicro · interscan messaging security virtual applianceAug 3, 2017
- CVE-2023-058754Plan
A file upload vulnerability in exists in Trend Micro Apex One server build 11110.
CriticalCVSS 9.1No exploitEPSS 60%trendmicro · apex oneJan 31, 2023