Vulnerabilities in Trend Micro, Inc.

180 results
Vexday analysis

O portfólio de vulnerabilidades da Trend Micro, Inc. reúne 180 CVEs catalogadas, das quais 3 estão confirmadas em exploração ativa no catálogo KEV da CISA — representando uma taxa 3,7 vezes acima da média geral do catálogo, sinal que merece atenção prioritária de equipes de resposta. A falha mais crítica em exploração ativa no momento é CVE-2025-54948, com pontuação EPSS de 0,2025, indicando probabilidade relevante de exploração continuada. O tipo de falha mais recorrente é CWE-346 (validação de origem em requisições), padrão que sugere fragilidades no controle de confiança entre componentes. Com 13 CVEs de severidade crítica, 16 surgidas nos últimos 90 dias e um EPSS máximo observado de 0,6894, o ritmo de novas exposições e o potencial de exploração justificam monitoramento contínuo e aplicação ágil de correções.

CVE-2023-38624MEDIUMA post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow aEPSS 0.3%CVE-2025-71216HIGHA time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate pEPSS 0.3%CVE-2023-38626MEDIUMA post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow aEPSS 0.3%CVE-2023-38627MEDIUMA post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow aEPSS 0.3%CVE-2023-38625MEDIUMA post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow aEPSS 0.3%CVE-2023-52092HIGHA security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected instalEPSS 0.3%CVE-2023-52090HIGHA security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected instalEPSS 0.3%CVE-2023-52091HIGHAn anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected EPSS 0.3%CVE-2023-52094HIGHAn updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbEPSS 0.3%CVE-2023-52338HIGHA link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could EPSS 0.3%CVE-2023-34145An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to EPSS 0.3%CVE-2023-34144An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to EPSS 0.3%CVE-2023-25144HIGHAn improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and creaEPSS 0.3%CVE-2025-71215HIGHA time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local aEPSS 0.3%CVE-2022-45798HIGHA link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could alEPSS 0.3%CVE-2026-45208HIGHA time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installaEPSS 0.3%CVE-2025-30679MEDIUMA Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manEPSS 0.3%CVE-2025-30678MEDIUMA Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manEPSS 0.3%CVE-2024-53647MEDIUMTrend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email veEPSS 0.3%CVE-2025-71217HIGHAn origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to eEPSS 0.3%