← Back

Trendmicro

trendmicro

559 CVEs • 105 products

Products (105)

Click to collapse
Toggle
Apex One
apex_one
Officescan
officescan
Apex Central
apex_central
Antivirus+
antivirus+
Serverprotect
serverprotect
Housecall
housecall
Security
security
Deep Security
deep_security
Scanmail
scanmail
Officescan Xg
officescan_xg
Dr. Safety
dr._safety
Im Security
im_security
Safe Lock
safe_lock
Cloud Edge
cloud_edge
Antivirus One
antivirus_one
Tmeext.sys
tmeext.sys
Ransom Buster
ransom_buster
Online Scan
online_scan
Rootkit Buster
rootkit_buster
Portal Protect
portal_protect

CVEs (559)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSD...Show more
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id paramete...Show more
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.
1Trendmicro
1Interscan Messaging Security Virtual Appliance
May 13, 2026
Apr 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass au...Show more
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Apr 5, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creat...Show more
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Apr 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dyn...Show more
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure passage for HTTPS connections. It also allows administrators to upload their own certificates signed by a root CA. An attacker with low privileges can download the current CA certificate and Private Key (either the default ones or ones uploaded by administrators) and use those to decrypt HTTPS traffic, thus compromising confidentiality. Also, the default Private Key on this appliance is encrypted with a very weak passphrase. If an appliance uses the default Certificate and Private Key provided by Trend Micro, an attacker can simply download these and decrypt the Private Key using the default/weak passphrase.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Apr 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Acc...Show more
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.Show less
1Trendmicro
1Mobile Security
May 13, 2026
Mar 31, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
1Trendmicro
4Antivirus+
Internet SecurityMaximum Security+1 more
May 13, 2026
Mar 21, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechan...Show more
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
May 13, 2026
Mar 14, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the d...Show more
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss endpoint takes several user inputs and performs blacklisting. After that, it uses them as arguments to a predefined operating-system command without proper sanitization. However, because of an improper blacklisting rule, it's possible to inject arbitrary commands into it.Show less
1Trendmicro
1Endpoint Sensor
May 13, 2026
Mar 10, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208.
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Feb 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and ea...Show more
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.Show less