← Back

Trendmicro

trendmicro

575 CVEs • 105 products

Products (105)

Click to collapse
Toggle
Apex One
apex_one
Officescan
officescan
Apex Central
apex_central
Antivirus+
antivirus+
Serverprotect
serverprotect
Housecall
housecall
Security
security
Deep Security
deep_security
Scanmail
scanmail
Officescan Xg
officescan_xg
Dr. Safety
dr._safety
Im Security
im_security
Safe Lock
safe_lock
Cloud Edge
cloud_edge
Antivirus One
antivirus_one
Tmeext.sys
tmeext.sys
Ransom Buster
ransom_buster
Online Scan
online_scan
Rootkit Buster
rootkit_buster
Portal Protect
portal_protect

CVEs (575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Officescan
May 13, 2026
Oct 6, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potentia...Show more
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.Show less
1Trendmicro
1Officescan
May 13, 2026
Oct 6, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
1Trendmicro
1Officescan
May 13, 2026
Oct 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.
1Trendmicro
1Officescan
May 13, 2026
Oct 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Sep 22, 2017
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement...Show more
Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.Show less
1Trendmicro
1Smart Protection Server
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.
1Trendmicro
1Control Manager
May 13, 2026
Aug 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.
1Trendmicro
1Officescan
May 13, 2026
Aug 3, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter...Show more
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.Show less
1Trendmicro
1Officescan
May 13, 2026
Aug 3, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter...Show more
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
May 13, 2026
Aug 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by...Show more
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
May 13, 2026
Aug 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by...Show more
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.Show less
1Trendmicro
1Deep Discovery Email Inspector
May 13, 2026
Aug 3, 2017
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.
1Trendmicro
1Control Manager
May 13, 2026
Aug 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
1Trendmicro
1Control Manager
May 13, 2026
Aug 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
1Trendmicro
1Control Manager
May 13, 2026
Aug 2, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and...Show more
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.Show less
1Trendmicro
1Control Manager
May 13, 2026
Aug 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.