Trendmicro
trendmicro
559 CVEs • 105 products
Products (105)
Click to collapseToggle
Products (105)
Click to collapse
CVEs (559)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSD...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id paramete...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value. |
1Trendmicro 1Interscan Messaging Security Virtual Appliance May 13, 2026 Apr 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass au...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. |
1Trendmicro 1Interscan Web Security Virtual Appliance May 13, 2026 Apr 5, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creat...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance May 13, 2026 Apr 5, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dyn...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance May 13, 2026 Apr 5, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Acc...Show more |
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398. |
1Trendmicro 4Antivirus+ Internet SecurityMaximum Security+1 moreMay 13, 2026 Mar 21, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechan...Show more |
1Trendmicro 1Interscan Messaging Security Virtual Appliance May 13, 2026 Mar 14, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the d...Show more |
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208. |
1Trendmicro 1Interscan Web Security Virtual Appliance May 13, 2026 Feb 21, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and ea...Show more |