Записи trendmicro
575 опубликованных записей вендора trendmicro.
Профиль для исследователя
- Попали в KEV
- 12 · 2,1 %
- С эксплойтом
- 24 · 4,2 %
- Pre-auth RCE
- 52
- С записью об исправлении
- 31,3 %
- Медиана: публикация → KEV
- 97 дн.
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')41
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')39
- CWE-269 Improper Privilege Management31
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')28
- CWE-427 Uncontrolled Search Path Element28
- CWE-346 Origin Validation Error24
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
575 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2025-54948Готовый эксплойт | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious trendmicro · apex one · CWE-78 | Критическая9,8 | KEV | 22,0 % | 5 авг. 2025 г. |
75На этой неделе | CVE-2022-26871Готовый эксплойт | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary filtrendmicro · apex central · CWE-345 | Критическая9,8 | KEV | 19,5 % | 29 мар. 2022 г. |
73На этой неделе | CVE-2020-8599Готовый эксплойт | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dattrendmicro · apex one | Критическая9,8 | KEV | 11,9 % | 17 мар. 2020 г. |
68На этой неделе | CVE-2019-18187Готовый эксплойт | Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extractrendmicro · officescan · CWE-22 | Высокая7,5 | KEV | 25,1 % | 28 окт. 2019 г. |
68На этой неделе | CVE-2020-8467Готовый эксплойт | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to etrendmicro · apex one | Высокая8,8 | KEV | 10,9 % | 17 мар. 2020 г. |
67На этой неделе | CVE-2016-7552Готовый эксплойт | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenttrendmicro · threat discovery appliance · CWE-22 | Критическая9,8 | — | 93,2 % | 12 апр. 2017 г. |
67На этой неделе | CVE-2016-7547Готовый эксплойт | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.ctrendmicro · threat discovery appliance · CWE-361 | Критическая9,8 | — | 92,7 % | 12 апр. 2017 г. |
67На этой неделе | CVE-2020-8468Готовый эксплойт | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | Высокая8,8 | KEV | 6,2 % | 17 мар. 2020 г. |
66На этой неделе | CVE-2021-36741Готовый эксплойт | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1trendmicro · officescan · CWE-434 | Высокая8,8 | KEV | 5,0 % | 29 июл. 2021 г. |
62На этой неделе | CVE-2020-24557Готовый эксплойт | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate amicrosoft · windows | Высокая7,8 | KEV | 2,7 % | 1 сент. 2020 г. |
61На этой неделе | CVE-2020-8605Готовый эксплойт | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affectedtrendmicro · interscan web security virtual appliance · CWE-78 | Высокая8,8 | — | 87,8 % | 27 мая 2020 г. |
61На этой неделе | CVE-2020-28578Эксплойта нет | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sptrendmicro · interscan web security virtual appliance · CWE-787 | Критическая9,8 | — | 73,0 % | 18 нояб. 2020 г. |
61На этой неделе | CVE-2020-8606Готовый эксплойт | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected trendmicro · interscan web security virtual appliance · CWE-287 | Критическая9,8 | — | 72,7 % | 27 мая 2020 г. |
61На этой неделе | CVE-2021-36742Готовый эксплойт | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.trendmicro · officescan · CWE-20 | Высокая7,8 | KEV | 1,5 % | 29 июл. 2021 г. |
59В плане | CVE-2017-11394Готовый эксплойт | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerabtrendmicro · officescan · CWE-20 | Критическая9,8 | — | 66,8 % | 3 авг. 2017 г. |
59В плане | CVE-2023-41179Готовый эксплойт | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security antrendmicro · apex one · CWE-94 | Высокая7,2 | KEV | 4,3 % | 19 сент. 2023 г. |
59В плане | CVE-2022-40139Готовый эксплойт | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients trendmicro · apex one | Высокая7,2 | KEV | 3,3 % | 19 сент. 2022 г. |
58В плане | CVE-2020-8466Эксплойта нет | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing methodtrendmicro · interscan web security virtual appliance · CWE-78 | Критическая9,8 | — | 64,1 % | 17 дек. 2020 г. |
57В плане | CVE-2020-8604Готовый эксплойт | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on trendmicro · interscan web security virtual appliance · CWE-22 | Высокая7,5 | — | 89,8 % | 27 мая 2020 г. |
56В плане | CVE-2023-32521Эксплойта нет | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated rtrendmicro · mobile security · CWE-22 | Критическая9,1 | — | 66,8 % | 26 июн. 2023 г. |
56В плане | CVE-2026-34926Готовый эксплойт | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tabletrendmicro · apex one · CWE-23 | Средняя6,7 | KEV | 0,5 % | 21 мая 2026 г. |
55В плане | CVE-2018-3604Эксплойта нет | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to trendmicro · control manager · CWE-89 | Высокая8,8 | — | 67,8 % | 9 февр. 2018 г. |
54В плане | CVE-2018-10357Эксплойта нет | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code trendmicro · endpoint application control · CWE-22 | Высокая8,8 | — | 64,7 % | 23 мая 2018 г. |
54В плане | CVE-2017-11391Готовый эксплойт | Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute artrendmicro · interscan messaging security virtual appliance · CWE-77 | Высокая8,8 | — | 61,8 % | 3 авг. 2017 г. |
54В плане | CVE-2023-0587Эксплойта нет | A file upload vulnerability in exists in Trend Micro Apex One server build 11110.trendmicro · apex one · CWE-434 | Критическая9,1 | — | 59,6 % | 31 янв. 2023 г. |
- CVE-2025-5494876На этой неделе
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 22 %trendmicro · apex one5 авг. 2025 г.
- CVE-2022-2687175На этой неделе
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary fil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 19 %trendmicro · apex central29 мар. 2022 г.
- CVE-2020-859973На этой неделе
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dat
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 12 %trendmicro · apex one17 мар. 2020 г.
- CVE-2019-1818768На этой неделе
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extrac
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 25 %trendmicro · officescan28 окт. 2019 г.
- CVE-2020-846768На этой неделе
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to e
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 11 %trendmicro · apex one17 мар. 2020 г.
- CVE-2016-755267На этой неделе
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthent
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %trendmicro · threat discovery appliance12 апр. 2017 г.
- CVE-2016-754767На этой неделе
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %trendmicro · threat discovery appliance12 апр. 2017 г.
- CVE-2020-846867На этой неделе
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 6 %trendmicro · apex one17 мар. 2020 г.
- CVE-2021-3674166На этой неделе
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 5 %trendmicro · officescan29 июл. 2021 г.
- CVE-2020-2455762На этой неделе
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %microsoft · windows1 сент. 2020 г.
- CVE-2020-860561На этой неделе
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected
ВысокаяCVSS 8,8Готовый эксплойтEPSS 88 %trendmicro · interscan web security virtual appliance27 мая 2020 г.
- CVE-2020-2857861На этой неделе
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sp
КритическаяCVSS 9,8Эксплойта нетEPSS 73 %trendmicro · interscan web security virtual appliance18 нояб. 2020 г.
- CVE-2020-860661На этой неделе
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected
КритическаяCVSS 9,8Готовый эксплойтEPSS 73 %trendmicro · interscan web security virtual appliance27 мая 2020 г.
- CVE-2021-3674261На этой неделе
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %trendmicro · officescan29 июл. 2021 г.
- CVE-2017-1139459В плане
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerab
КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %trendmicro · officescan3 авг. 2017 г.
- CVE-2023-4117959В плане
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security an
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 4 %trendmicro · apex one19 сент. 2023 г.
- CVE-2022-4013959В плане
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 3 %trendmicro · apex one19 сент. 2022 г.
- CVE-2020-846658В плане
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method
КритическаяCVSS 9,8Эксплойта нетEPSS 64 %trendmicro · interscan web security virtual appliance17 дек. 2020 г.
- CVE-2020-860457В плане
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on
ВысокаяCVSS 7,5Готовый эксплойтEPSS 90 %trendmicro · interscan web security virtual appliance27 мая 2020 г.
- CVE-2023-3252156В плане
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated r
КритическаяCVSS 9,1Эксплойта нетEPSS 67 %trendmicro · mobile security26 июн. 2023 г.
- CVE-2026-3492656В плане
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table
СредняяCVSS 6,7KEVГотовый эксплойтEPSS 1 %trendmicro · apex one21 мая 2026 г.
- CVE-2018-360455В плане
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to
ВысокаяCVSS 8,8Эксплойта нетEPSS 68 %trendmicro · control manager9 февр. 2018 г.
- CVE-2018-1035754В плане
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code
ВысокаяCVSS 8,8Эксплойта нетEPSS 65 %trendmicro · endpoint application control23 мая 2018 г.
- CVE-2017-1139154В плане
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute ar
ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %trendmicro · interscan messaging security virtual appliance3 авг. 2017 г.
- CVE-2023-058754В плане
A file upload vulnerability in exists in Trend Micro Apex One server build 11110.
КритическаяCVSS 9,1Эксплойта нетEPSS 60 %trendmicro · apex one31 янв. 2023 г.