Vulnerabilities in Trend Micro, Inc.

180 results
Vexday analysis

O portfólio de vulnerabilidades da Trend Micro, Inc. reúne 180 CVEs catalogadas, das quais 3 estão confirmadas em exploração ativa no catálogo KEV da CISA — representando uma taxa 3,7 vezes acima da média geral do catálogo, sinal que merece atenção prioritária de equipes de resposta. A falha mais crítica em exploração ativa no momento é CVE-2025-54948, com pontuação EPSS de 0,2025, indicando probabilidade relevante de exploração continuada. O tipo de falha mais recorrente é CWE-346 (validação de origem em requisições), padrão que sugere fragilidades no controle de confiança entre componentes. Com 13 CVEs de severidade crítica, 16 surgidas nos últimos 90 dias e um EPSS máximo observado de 0,6894, o ritmo de novas exposições e o potencial de exploração justificam monitoramento contínuo e aplicação ágil de correções.

CVE-2023-32556A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitivEPSS 0.3%CVE-2022-28339HIGHTrend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could alEPSS 0.3%CVE-2025-49215HIGHA post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges oEPSS 0.3%CVE-2024-55917HIGHAn origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installatioEPSS 0.3%CVE-2024-32849HIGHTrend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionaEPSS 0.3%CVE-2025-31285MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator EPSS 0.3%CVE-2025-31283MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administratorEPSS 0.3%CVE-2025-31282MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administratEPSS 0.3%CVE-2025-31284MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to EPSS 0.3%CVE-2025-30680HIGHA Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameteEPSS 0.2%CVE-2025-47866MEDIUMAn unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbiEPSS 0.2%CVE-2026-34929HIGHAn origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. EPSS 0.2%CVE-2026-34927HIGHAn origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. EPSS 0.2%CVE-2025-49487MEDIUMAn uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacEPSS 0.2%CVE-2023-47192HIGHAn agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected instaEPSS 0.2%CVE-2023-52337HIGHAn improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent EPSS 0.2%CVE-2023-34147An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attackeEPSS 0.2%CVE-2023-34148An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attackeEPSS 0.2%CVE-2023-34146An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attackeEPSS 0.2%CVE-2023-25147MEDIUMAn issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypaEPSS 0.2%