trendmicro kayıtları
trendmicro üreticisine ait 575 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 12 · %2,1
- Silahlaştırılmış
- 24 · %4,2
- Pre-auth RCE
- 52
- Düzeltme kaydı olan
- %31,3
- Yayından KEV’e ortanca
- 97 gün
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')41
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')39
- CWE-269 Improper Privilege Management31
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')28
- CWE-427 Uncontrolled Search Path Element28
- CWE-346 Origin Validation Error24
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
575 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2025-54948Silahlaştırılmış | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious trendmicro · apex one · CWE-78 | Kritik9,8 | KEV | %22,0 | 5 Ağu 2025 |
75Bu hafta | CVE-2022-26871Silahlaştırılmış | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary filtrendmicro · apex central · CWE-345 | Kritik9,8 | KEV | %19,5 | 29 Mar 2022 |
73Bu hafta | CVE-2020-8599Silahlaştırılmış | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dattrendmicro · apex one | Kritik9,8 | KEV | %11,9 | 17 Mar 2020 |
68Bu hafta | CVE-2019-18187Silahlaştırılmış | Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extractrendmicro · officescan · CWE-22 | Yüksek7,5 | KEV | %25,1 | 28 Eki 2019 |
68Bu hafta | CVE-2020-8467Silahlaştırılmış | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to etrendmicro · apex one | Yüksek8,8 | KEV | %10,9 | 17 Mar 2020 |
67Bu hafta | CVE-2016-7552Silahlaştırılmış | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenttrendmicro · threat discovery appliance · CWE-22 | Kritik9,8 | — | %93,2 | 12 Nis 2017 |
67Bu hafta | CVE-2016-7547Silahlaştırılmış | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.ctrendmicro · threat discovery appliance · CWE-361 | Kritik9,8 | — | %92,7 | 12 Nis 2017 |
67Bu hafta | CVE-2020-8468Silahlaştırılmış | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | Yüksek8,8 | KEV | %6,2 | 17 Mar 2020 |
66Bu hafta | CVE-2021-36741Silahlaştırılmış | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1trendmicro · officescan · CWE-434 | Yüksek8,8 | KEV | %5,0 | 29 Tem 2021 |
62Bu hafta | CVE-2020-24557Silahlaştırılmış | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate amicrosoft · windows | Yüksek7,8 | KEV | %2,7 | 1 Eyl 2020 |
61Bu hafta | CVE-2020-8605Silahlaştırılmış | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affectedtrendmicro · interscan web security virtual appliance · CWE-78 | Yüksek8,8 | — | %87,8 | 27 May 2020 |
61Bu hafta | CVE-2020-28578İstismar yok | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sptrendmicro · interscan web security virtual appliance · CWE-787 | Kritik9,8 | — | %73,0 | 18 Kas 2020 |
61Bu hafta | CVE-2020-8606Silahlaştırılmış | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected trendmicro · interscan web security virtual appliance · CWE-287 | Kritik9,8 | — | %72,7 | 27 May 2020 |
61Bu hafta | CVE-2021-36742Silahlaştırılmış | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.trendmicro · officescan · CWE-20 | Yüksek7,8 | KEV | %1,5 | 29 Tem 2021 |
59Planlayın | CVE-2017-11394Silahlaştırılmış | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerabtrendmicro · officescan · CWE-20 | Kritik9,8 | — | %66,8 | 3 Ağu 2017 |
59Planlayın | CVE-2023-41179Silahlaştırılmış | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security antrendmicro · apex one · CWE-94 | Yüksek7,2 | KEV | %4,3 | 19 Eyl 2023 |
59Planlayın | CVE-2022-40139Silahlaştırılmış | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients trendmicro · apex one | Yüksek7,2 | KEV | %3,3 | 19 Eyl 2022 |
58Planlayın | CVE-2020-8466İstismar yok | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing methodtrendmicro · interscan web security virtual appliance · CWE-78 | Kritik9,8 | — | %64,1 | 17 Ara 2020 |
57Planlayın | CVE-2020-8604Silahlaştırılmış | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on trendmicro · interscan web security virtual appliance · CWE-22 | Yüksek7,5 | — | %89,8 | 27 May 2020 |
56Planlayın | CVE-2023-32521İstismar yok | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated rtrendmicro · mobile security · CWE-22 | Kritik9,1 | — | %66,8 | 26 Haz 2023 |
56Planlayın | CVE-2026-34926Silahlaştırılmış | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tabletrendmicro · apex one · CWE-23 | Orta6,7 | KEV | %0,5 | 21 May 2026 |
55Planlayın | CVE-2018-3604İstismar yok | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to trendmicro · control manager · CWE-89 | Yüksek8,8 | — | %67,8 | 9 Şub 2018 |
54Planlayın | CVE-2018-10357İstismar yok | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code trendmicro · endpoint application control · CWE-22 | Yüksek8,8 | — | %64,7 | 23 May 2018 |
54Planlayın | CVE-2017-11391Silahlaştırılmış | Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute artrendmicro · interscan messaging security virtual appliance · CWE-77 | Yüksek8,8 | — | %61,8 | 3 Ağu 2017 |
54Planlayın | CVE-2023-0587İstismar yok | A file upload vulnerability in exists in Trend Micro Apex One server build 11110.trendmicro · apex one · CWE-434 | Kritik9,1 | — | %59,6 | 31 Oca 2023 |
- CVE-2025-5494876Bu hafta
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %22trendmicro · apex one5 Ağu 2025
- CVE-2022-2687175Bu hafta
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary fil
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %19trendmicro · apex central29 Mar 2022
- CVE-2020-859973Bu hafta
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary dat
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %12trendmicro · apex one17 Mar 2020
- CVE-2019-1818768Bu hafta
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extrac
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %25trendmicro · officescan28 Eki 2019
- CVE-2020-846768Bu hafta
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to e
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %11trendmicro · apex one17 Mar 2020
- CVE-2016-755267Bu hafta
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthent
KritikCVSS 9,8SilahlaştırılmışEPSS %93trendmicro · threat discovery appliance12 Nis 2017
- CVE-2016-754767Bu hafta
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c
KritikCVSS 9,8SilahlaştırılmışEPSS %93trendmicro · threat discovery appliance12 Nis 2017
- CVE-2020-846867Bu hafta
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %6trendmicro · apex one17 Mar 2020
- CVE-2021-3674166Bu hafta
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 1
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %5trendmicro · officescan29 Tem 2021
- CVE-2020-2455762Bu hafta
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3microsoft · windows1 Eyl 2020
- CVE-2020-860561Bu hafta
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected
YüksekCVSS 8,8SilahlaştırılmışEPSS %88trendmicro · interscan web security virtual appliance27 May 2020
- CVE-2020-2857861Bu hafta
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a sp
KritikCVSS 9,8İstismar yokEPSS %73trendmicro · interscan web security virtual appliance18 Kas 2020
- CVE-2020-860661Bu hafta
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected
KritikCVSS 9,8SilahlaştırılmışEPSS %73trendmicro · interscan web security virtual appliance27 May 2020
- CVE-2021-3674261Bu hafta
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1trendmicro · officescan29 Tem 2021
- CVE-2017-1139459Planlayın
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerab
KritikCVSS 9,8SilahlaştırılmışEPSS %67trendmicro · officescan3 Ağu 2017
- CVE-2023-4117959Planlayın
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security an
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4trendmicro · apex one19 Eyl 2023
- CVE-2022-4013959Planlayın
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %3trendmicro · apex one19 Eyl 2022
- CVE-2020-846658Planlayın
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method
KritikCVSS 9,8İstismar yokEPSS %64trendmicro · interscan web security virtual appliance17 Ara 2020
- CVE-2020-860457Planlayın
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on
YüksekCVSS 7,5SilahlaştırılmışEPSS %90trendmicro · interscan web security virtual appliance27 May 2020
- CVE-2023-3252156Planlayın
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated r
KritikCVSS 9,1İstismar yokEPSS %67trendmicro · mobile security26 Haz 2023
- CVE-2026-3492656Planlayın
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table
OrtaCVSS 6,7KEVSilahlaştırılmışEPSS %1trendmicro · apex one21 May 2026
- CVE-2018-360455Planlayın
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to
YüksekCVSS 8,8İstismar yokEPSS %68trendmicro · control manager9 Şub 2018
- CVE-2018-1035754Planlayın
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code
YüksekCVSS 8,8İstismar yokEPSS %65trendmicro · endpoint application control23 May 2018
- CVE-2017-1139154Planlayın
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute ar
YüksekCVSS 8,8SilahlaştırılmışEPSS %62trendmicro · interscan messaging security virtual appliance3 Ağu 2017
- CVE-2023-058754Planlayın
A file upload vulnerability in exists in Trend Micro Apex One server build 11110.
KritikCVSS 9,1İstismar yokEPSS %60trendmicro · apex one31 Oca 2023