Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-14963
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system p…
Endpoint Security
after 34.0.0
MEDIUM 5.5
CVE-2025-3773
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to …
System Information Reporter
after 1.0.3
HIGH 7.1
CVE-2025-3771
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system f…
System Information Reporter
after 1.0.3
CRITICAL 9.8
CVE-2024-11482
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command inject…
Enterprise Security Manager
No fix yet
HIGH 8.2
CVE-2024-11481
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, inse…
Enterprise Security Manager
Mitigation only
HIGH 7.5
CVE-2024-5957
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
Intrusion Prevention System Manager
11.1.7.97+
MEDIUM 5.3
CVE-2024-5956
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manage…
Intrusion Prevention System Manager
Mitigation only
MEDIUM 5.4
CVE-2024-4176
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using…
Xconsole
after 2024-05-17
MEDIUM 5.4
CVE-2023-6072
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashb…
Central Management System
9.1.3.97129+
MEDIUM 6.1
CVE-2024-0310
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response hea…
Endpoint Security Web Control
10.7.0+
HIGH 7.8
CVE-2024-0206
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to pot…
Anti Malware Engine
Mitigation only
HIGH 7.8
CVE-2024-0213
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial o…
Agent
5.8.1+
HIGH 7.2
CVE-2023-6071
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execut…
Enterprise Security Manager
11.6.9+
HIGH 7.2
CVE-2023-5607
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers…
Application And Change Control
8.4.0+
HIGH 7.8
CVE-2023-6119
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to …
Getsusp
5.0.0.27+
HIGH 7.8
CVE-2023-3665
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir…
Endpoint Security
after 10.7.0
HIGH 7.1
CVE-2023-4814
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the u…
Data Loss Prevention
Mitigation only
HIGH 8.8
CVE-2023-3314
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands u…
Enterprise Security Manager
11.6.7+
HIGH 7.8
CVE-2023-3313
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthor…
Enterprise Security Manager
11.6.7+
HIGH 7.8
CVE-2023-3438
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
The misconf…
Move
after 4.10.0
HIGH 8.1
CVE-2023-1388
A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, re…
Agent
5.7.9+
HIGH 7.8
CVE-2023-0976
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Age…
Agent
5.7.9+
HIGH 7.8
CVE-2023-0975
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace o…
Agent
after 5.7.8
MEDIUM 6.5
CVE-2023-0977
A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in th…
Agent
after 5.7.8
HIGH 8.2
CVE-2023-0400
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when …
Data Loss Prevention
11.10.0+
MEDIUM 6.1
CVE-2023-0214
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior t…
Skyhigh Secure Web Gateway
10.2.17 / 11.2.6+
MEDIUM 6.0
CVE-2022-4326
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administ…
Endpoint Security
35.31.22+
MEDIUM 6.7
CVE-2022-3859
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin ac…
Agent
5.7.8+
HIGH 7.2
CVE-2022-3340
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in …
Intrusion Prevention System Manager
10.1+